jinchenma-ip-article-illustrations

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes text from external sources (URLs and local files) to conceptualize illustrations, which is a standard surface for indirect prompt injection. This behavior is fundamental to the skill's purpose.\n
  • Ingestion points: The skill accepts web links and local Markdown/text file paths as input in 'references/article-workflow.md'.\n
  • Boundary markers: There are no explicit instructions or delimiters mentioned to separate untrusted content from the agent's internal instructions.\n
  • Capability inventory: The agent has the ability to read local files, fetch web content, generate images via internal tools, and write files to the local filesystem.\n
  • Sanitization: The skill does not describe any specific validation or filtering mechanisms for the ingested text.\n- [SAFE]: The skill demonstrates secure file handling practices for its configuration and asset management.\n
  • Evidence: 'references/ip-pack-format.md' explicitly mandates validation to block directory traversal attacks and the use of absolute paths when importing character IP packages from external sources or builder directories.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:34 PM
Security Audit — agent-trust-hub — jinchenma-ip-article-illustrations