baoyu-infographic
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill employs a dynamic script discovery and execution method. It searches for
packages/baoyu-codex-imagegen/src/main.tswithin the local environment and executes it using thebunruntime. Users can also define a specific binary path via theBAOYU_CODEX_IMAGEGEN_BINenvironment variable.- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes external content to generate instructions for image generation tools. 1. Ingestion points: Source material provided insource.mdand user-defined design instructions. 2. Boundary markers: Thereferences/base-prompt.mdtemplate places user content into{{CONTENT}}without protective delimiters or instructions to ignore nested commands. 3. Capability inventory: The skill can write files to the local system and execute shell commands for backend invocation. 4. Sanitization: The skill explicitly removes sensitive credentials from its output but lacks specific validation to prevent prompt injection attacks.- [EXTERNAL_DOWNLOADS]: The execution of thecodex-imagegenwrapper relies onnpx -y bun, which may download thebunpackage from the npm registry if it is not already present on the host system.- [COMMAND_EXECUTION]: The skill programmatically invokes external command-line utilities and sibling skills such asbaoyu-image-gento perform rendering tasks, passing absolute file paths and generated prompt strings as arguments.
Audit Metadata