jinchenma-ip-article-illustrations
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes text from external sources (URLs and local files) to conceptualize illustrations, which is a standard surface for indirect prompt injection. This behavior is fundamental to the skill's purpose.\n
- Ingestion points: The skill accepts web links and local Markdown/text file paths as input in 'references/article-workflow.md'.\n
- Boundary markers: There are no explicit instructions or delimiters mentioned to separate untrusted content from the agent's internal instructions.\n
- Capability inventory: The agent has the ability to read local files, fetch web content, generate images via internal tools, and write files to the local filesystem.\n
- Sanitization: The skill does not describe any specific validation or filtering mechanisms for the ingested text.\n- [SAFE]: The skill demonstrates secure file handling practices for its configuration and asset management.\n
- Evidence: 'references/ip-pack-format.md' explicitly mandates validation to block directory traversal attacks and the use of absolute paths when importing character IP packages from external sources or builder directories.
Audit Metadata