baoyu-xhs-images
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted text content to generate structured infographics, creating an indirect prompt injection attack surface.
- Ingestion points: External source material enters the workflow during the content analysis phase and is stored as
source-{slug}.{ext}as documented inSKILL.mdandreferences/workflows/analysis-framework.md. - Boundary markers: The template assembly uses clear structural headers like
## Contentand horizontal markdown rules (---) to scope content blocks inreferences/workflows/prompt-assembly.md. - Capability inventory: The skill performs local file system modifications (saving
analysis.md,outline.md, and prompt configurations) and issues subprocess/tool invocations to run image backends (such as spawning the localcodex-imagegentool viabun) as detailed inSKILL.mdandreferences/codex-imagegen.md. - Sanitization: No specific content sanitization or alphanumeric filtering for input validation is implemented prior to structural extraction.
Audit Metadata