ludamo-xuexi

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a structured knowledge base and interactive guide. It consists entirely of Markdown and YAML configuration files, with no associated scripts (Python, JavaScript, or Shell) or binary executables.
  • [PROMPT_INJECTION]: The instructions are designed to manage an interactive learning flow and do not contain patterns aimed at overriding safety guidelines or extracting system prompts. A potential indirect injection surface exists where user business descriptions are ingested for routing to a diagnostic tool, but this is benign given the absence of any exploitable tools or file-system capabilities. (Ingestion points: 用户原话 in SKILL.md; Boundary markers: None; Capability inventory: None; Sanitization: None).
  • [DATA_EXFILTRATION]: No sensitive data access patterns, environment variable exposure, or hardcoded credentials were detected. The skill does not possess network tools like curl or wget to transmit data to external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 03:15 PM
Security Audit — agent-trust-hub — ludamo-xuexi