baoyu-cover-image

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill implements a runtime discovery mechanism to locate and execute image generation wrappers. In references/codex-imagegen.md, it instructs the agent to search for a script file (main.ts) by walking up the directory tree or by using a path provided in an environment variable (BAOYU_CODEX_IMAGEGEN_BIN). It then executes this discovered path using bun or npx. This reliance on computed paths for execution introduces risks related to path manipulation if the environment or file structure is not tightly controlled.- [COMMAND_EXECUTION]: The skill invokes external command-line tools including baoyu-image-gen, codex, bun, and npx. These commands are executed with arguments derived from user input and file content (e.g., prompt files and output paths), which increases the attack surface for command injection if inputs are not strictly validated.- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests article content to generate image prompts without adequate isolation. Ingestion points: Article source files saved in Step 1 and user input tools. Boundary markers: The prompt template in references/workflow/prompt-template.md uses section headers but lacks explicit safety delimiters or 'ignore' instructions for the content being processed. Capability inventory: The skill can write to the local filesystem (prompts/, refs/, outputs/) and execute shell commands through multiple backend providers. Sanitization: No explicit sanitization or filtering of the article content is described before it is interpolated into the final generation prompt.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:55 AM
Security Audit — agent-trust-hub — baoyu-cover-image