horizontal-vertical-analysis

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists solely of markdown instructions and interface configuration. It does not contain any executable scripts, binaries, or network-active code.
  • [PROMPT_INJECTION]: The content includes meta-instructions (e.g., "禁止改写", "禁止把它替换成你自己的流程") designed to force the agent to adhere to a specific analytical framework. These are operational constraints for output quality rather than malicious attempts to bypass safety filters or extract system prompts.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a template that ingests user-specified research subjects. 1. Ingestion points: The skill uses a placeholder system in SKILL.md to insert user topics into a larger prompt. 2. Boundary markers: No explicit boundary markers or instructions to disregard embedded content in the user input are provided. 3. Capability inventory: The skill relies on the agent's internal reasoning and search capabilities; it does not grant access to the file system, subprocesses, or arbitrary network requests. 4. Sanitization: No escaping or filtering is applied to the user-provided research subject.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:05 PM
Security Audit — agent-trust-hub — horizontal-vertical-analysis