baoyu-article-illustrator

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: In prompts/system.md, the instructions explicitly command the system to bypass standard safeguards regarding copyrighted figures by stating "DO NOT refuse to generate", which can lead to safety policy violations.
  • [COMMAND_EXECUTION]: In references/codex-imagegen.md, the skill directs the agent to execute shell commands using bun or npx on paths dynamically retrieved from an environment variable ($BAOYU_CODEX_IMAGEGEN_BIN) or via directory walking, creating a risk of arbitrary command execution if the execution environment is untrusted.
  • [INDIRECT_PROMPT_INJECTION]: The workflow involves ingestion and processing of untrusted external content (articles or pasted user text), which introduces an indirect prompt injection surface.
  • Ingestion points: User-provided article files or pasted text parsed during Step 2 of the workflow (SKILL.md).
  • Boundary markers: Absent; there are no clear delimiters or escaping rules defined to prevent malicious text inside an article from hijacking subsequent prompt assembly steps.
  • Capability inventory: The skill possesses file write capabilities (outline.md, prompt files) and shell execution tools through image generation wrappers.
  • Sanitization: No sanitization, validation, or structural isolation is performed on the ingested text before it is inserted into the final prompt templates.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:55 AM
Security Audit — agent-trust-hub — baoyu-article-illustrator