xiaodou-cover-generator
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user content to generate visual concepts, exposing it to indirect prompt injection.\n
- Ingestion points: Receives article text and themes in SKILL.md.\n
- Boundary markers: None identified; user input is not delimited from instructions.\n
- Capability inventory: Utilizes the
generate_imagetool.\n - Sanitization: No sanitization of user input is documented.\n- [DATA_EXFILTRATION]: Multiple reference files (case_analysis.md, infographic_4grid_guide.md, ip_prompt_guide.md) contain hardcoded absolute file paths pointing to the author's local desktop (file:///Users/suxiaohan/Desktop/...). This reveals the user's local directory structure and system username.
Audit Metadata