gc-minimal-zine-poster-v0-3

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists of markdown instructions, configuration files, and metadata. It does not include any executable scripts, binary files, or external code dependencies.
  • [PROMPT_INJECTION]: The skill processes external data such as user-supplied articles and images to generate visual metaphors. This creates a potential surface for indirect prompt injection if input data contains adversarial instructions.
  • Ingestion points: User themes, articles, and reference images are processed through the routes defined in SKILL.md and references/reference-analysis.md.
  • Boundary markers: The skill includes logic in references/quality-gate.md to prevent the literal reproduction of source text or brands, though it lacks structural delimiters for raw input strings.
  • Capability inventory: The skill is limited to built-in image generation and does not have file-write or network-egress capabilities.
  • Sanitization: Input content is analyzed for conceptual meaning rather than sanitized via filtering.
  • [SAFE]: Remote resources referenced in the documentation, such as the GitHub repository for installation, are owned by the skill's author (liamgvchi), representing standard distribution of vendor resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 11:57 AM
Security Audit — agent-trust-hub — gc-minimal-zine-poster-v0-3