gc-minimal-zine-poster-v0-3
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists of markdown instructions, configuration files, and metadata. It does not include any executable scripts, binary files, or external code dependencies.
- [PROMPT_INJECTION]: The skill processes external data such as user-supplied articles and images to generate visual metaphors. This creates a potential surface for indirect prompt injection if input data contains adversarial instructions.
- Ingestion points: User themes, articles, and reference images are processed through the routes defined in SKILL.md and references/reference-analysis.md.
- Boundary markers: The skill includes logic in references/quality-gate.md to prevent the literal reproduction of source text or brands, though it lacks structural delimiters for raw input strings.
- Capability inventory: The skill is limited to built-in image generation and does not have file-write or network-egress capabilities.
- Sanitization: Input content is analyzed for conceptual meaning rather than sanitized via filtering.
- [SAFE]: Remote resources referenced in the documentation, such as the GitHub repository for installation, are owned by the skill's author (liamgvchi), representing standard distribution of vendor resources.
Audit Metadata