satoshi-kon-perspective

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill exposes the creator's local system metadata through the inclusion of absolute file paths in the documentation.
  • Evidence: The 'Appendix' section in SKILL.md lists absolute paths: /Users/baimengke/Documents/白梦客知识库/01-导演组/今敏深度研究.md and /Users/baimengke/Documents/白梦客知识库/01-导演组/今敏美学风格指南.md.
  • Impact: This reveals the local username ('baimengke') and the internal directory structure of the creator's machine.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection via user-supplied creative inputs.
  • Ingestion points: User input regarding 'topics', 'dreams', and 'stories' is ingested and processed in Phase 1 of the workflow described in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard instructions embedded within user-provided creative text.
  • Capability inventory: The skill is configured for text-based persona responses and does not currently invoke any filesystem, network, or system-level tools.
  • Sanitization: No filtering or validation mechanisms are defined to sanitize external content before it is interpolated into the creative analysis workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — satoshi-kon-perspective