laohan-fengmianqiuzhi

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from local video scripts, creating a surface for indirect prompt injection.
  • Ingestion points: The skill reads 01-口播稿.md to extract video titles and visual keywords.
  • Boundary markers: The skill lacks explicit delimiters or instructions to prevent the agent from executing commands that might be embedded within the script text.
  • Capability inventory: The agent is instructed to call an external image generation tool and write multiple files to the local file system based on the processed content.
  • Sanitization: There is no evidence of input validation, escaping, or filtering of the script content before it is interpolated into the final image generation prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 02:23 AM
Security Audit — agent-trust-hub — laohan-fengmianqiuzhi