wjs-voicedrop-choosing-cover

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill does not contain any evidence of malicious patterns, such as prompt injection bypasses, credential harvesting, or persistence mechanisms.
  • [DATA_EXPOSURE]: The skill reads article content to perform its task but does not attempt to access sensitive configuration files (.env, .ssh, .aws) or hardcode secrets.
  • [COMMAND_EXECUTION]: No unauthorized shell commands or privilege escalation attempts were detected. The skill interacts with predefined tools like 'read_article' and 'gpt-image-2-skill' for its intended purpose.
  • [EXTERNAL_DOWNLOADS]: The skill does not download external scripts or install third-party packages at runtime.
  • [SAFE]: The skill processes untrusted article content (via MCP read_article or pasted text), which is an indirect prompt injection surface. However, the risk is negligible as the output is restricted to image generation prompts, and no sensitive capabilities are exposed to this data flow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 03:14 AM
Security Audit — agent-trust-hub — wjs-voicedrop-choosing-cover