li-human
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill operates as a local utility for text processing. Analysis of
humanize.pyanddetect.pyshows standard file I/O and text manipulation logic using the built-inreandunicodedatamodules. - [SAFE]: No network operations, external downloads, or third-party dependencies are detected. All processing is performed locally on user-provided input files using the provided scripts and lexicon.
- [SAFE]: The skill includes functionality to detect and strip hidden Unicode characters (tags, zero-width joiners, etc.) that can be used for watermarking or data smuggling. This is a security-positive feature designed to protect the user's privacy and text integrity.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided text files.
- Ingestion points: The scripts
humanize.pyanddetect.pyread arbitrary text from files passed as command-line arguments (e.g.,draft.txt). - Boundary markers: Absent. The input text is treated as raw content for analysis and replacement.
- Capability inventory: The scripts perform file reads and writes (via the
-oflag inhumanize.py), but do not perform network operations or command execution on input data. - Sanitization: Present.
humanize.pyis designed to sanitize text by removing invisible characters and specific lexical patterns.
Audit Metadata