baoyu-article-illustrator
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: In
prompts/system.md, the instructions explicitly command the system to bypass standard safeguards regarding copyrighted figures by stating "DO NOT refuse to generate", which can lead to safety policy violations. - [COMMAND_EXECUTION]: In
references/codex-imagegen.md, the skill directs the agent to execute shell commands usingbunornpxon paths dynamically retrieved from an environment variable ($BAOYU_CODEX_IMAGEGEN_BIN) or via directory walking, creating a risk of arbitrary command execution if the execution environment is untrusted. - [INDIRECT_PROMPT_INJECTION]: The workflow involves ingestion and processing of untrusted external content (articles or pasted user text), which introduces an indirect prompt injection surface.
- Ingestion points: User-provided article files or pasted text parsed during Step 2 of the workflow (
SKILL.md). - Boundary markers: Absent; there are no clear delimiters or escaping rules defined to prevent malicious text inside an article from hijacking subsequent prompt assembly steps.
- Capability inventory: The skill possesses file write capabilities (
outline.md, prompt files) and shell execution tools through image generation wrappers. - Sanitization: No sanitization, validation, or structural isolation is performed on the ingested text before it is inserted into the final prompt templates.
Audit Metadata