baoyu-infographic

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill employs a dynamic script discovery and execution method. It searches for packages/baoyu-codex-imagegen/src/main.ts within the local environment and executes it using the bun runtime. Users can also define a specific binary path via the BAOYU_CODEX_IMAGEGEN_BIN environment variable.- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes external content to generate instructions for image generation tools. 1. Ingestion points: Source material provided in source.md and user-defined design instructions. 2. Boundary markers: The references/base-prompt.md template places user content into {{CONTENT}} without protective delimiters or instructions to ignore nested commands. 3. Capability inventory: The skill can write files to the local system and execute shell commands for backend invocation. 4. Sanitization: The skill explicitly removes sensitive credentials from its output but lacks specific validation to prevent prompt injection attacks.- [EXTERNAL_DOWNLOADS]: The execution of the codex-imagegen wrapper relies on npx -y bun, which may download the bun package from the npm registry if it is not already present on the host system.- [COMMAND_EXECUTION]: The skill programmatically invokes external command-line utilities and sibling skills such as baoyu-image-gen to perform rendering tasks, passing absolute file paths and generated prompt strings as arguments.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:58 AM
Security Audit — agent-trust-hub — baoyu-infographic