shitiesheng-perspective
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No instructions were found that attempt to bypass safety guidelines, override system behavior, or extract system prompts. The 'Identity Card' and 'Working Flow' sections are standard stylistic framing for persona emulation.
- [DATA_EXFILTRATION]: The skill does not contain hardcoded credentials, sensitive file paths (such as .ssh or .env), or network calls to non-whitelisted domains. It does not attempt to access or transmit environment variables or sensitive local data.
- [EXTERNAL_DOWNLOADS]: The skill references a GitHub repository (github.com/alchaincyf/nuwa-skill) in its footer. This is a neutral reference to a well-known service for documentation and project hosting.
- [REMOTE_CODE_EXECUTION]: No patterns for downloading and executing remote scripts or installing unverified external packages were detected. The skill does not include package management files or runtime execution commands.
- [COMMAND_EXECUTION]: The instructions and research files do not contain shell commands, subprocess calls, or scripts that interact with the host system's command line.
- [DYNAMIC_CONTEXT_INJECTION]: The skill does not use the shell command execution syntax ('!command') inside the SKILL.md file.
- [SAFE]: All 10 threat categories were evaluated, including obfuscation and persistence mechanisms; no suspicious behaviors or indicators of compromise were found.
Audit Metadata