nihaixia

Pass

Audited by Gen Agent Trust Hub on Jun 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions in SKILL.md and beginner-questions.md are focused on educational distillation and user routing. They do not attempt to override system safety filters or engage in role-play jailbreaking.
  • [DATA_EXFILTRATION]: No hardcoded credentials or sensitive file paths were found. The skill does not perform any network operations; it operates entirely on bundled local reference files.
  • [REMOTE_CODE_EXECUTION]: There are no patterns of remote script execution (e.g., curl | bash). The Python scripts provided (search_screenshots.py and build_screenshot_assets.py) are for local metadata indexing and image processing.
  • [COMMAND_EXECUTION]: The skill uses a local Python script (search_screenshots.py) for searching its own database. The input to this script is used for string scoring and does not flow into any dynamic execution sinks.
  • [EXTERNAL_DOWNLOADS]: References to external sources are limited to the official project repository on GitHub, which is a standard and safe practice for skill distribution.
  • [SAFE]: The skill includes extensive health warnings and instructions for the agent to refer users to licensed professionals for actual medical needs, maintaining a clear educational boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 2, 2026, 12:44 PM
Security Audit — agent-trust-hub — nihaixia