two-layer-explain

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-provided content, including specific concepts, documents, links, and chat histories, which creates a potential surface for indirect prompt injection.
  • Ingestion points: The skill explicitly instructs the agent to fill the placeholder 【填写概念或问题】 with user input and to read external materials like documents, screenshots, links, and chat records.
  • Boundary markers: No specific delimiters or boundary markers are defined to separate user-provided data from the skill's system instructions.
  • Capability inventory: The skill primarily performs text analysis and generation. It does not request access to sensitive tools, network operations, or file system modifications.
  • Sanitization: The instructions do not include specific sanitization or validation steps for the external content before it is processed by the model.
  • [PROMPT_INJECTION]: The instructions use highly restrictive and imperative language (e.g., "禁止改写"/"Prohibit modification", "一个字不改"/"Do not change a single word") to enforce a specific output format. While these are stylistic constraints for the agent, this technique of "metaprompting" is used to strictly control agent behavior and suppress modifications to the provided prompt template.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:05 PM
Security Audit — agent-trust-hub — two-layer-explain