shaoniannu-perspective

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily a personality and mindset framework for an AI agent to emulate a specific auditing professional. The instructions focus on tone, style, and professional judgment, with no commands directed toward subverting system security or safety filters.\n- [INDIRECT_PROMPT_INJECTION]: The skill workflow includes a research step (Step 2) that ingests external data from the web to provide accurate auditing facts. This is an inherent attack surface for indirect prompt injection where external content could attempt to influence the agent's behavior.\n
  • Ingestion points: Data retrieved via WebSearch and user-provided queries.\n
  • Boundary markers: Absent. The instructions do not explicitly tell the agent to ignore instructions found within external search results.\n
  • Capability inventory: The skill is configured to use standard search tools. No high-privilege capabilities like terminal access or file system modification are requested.\n
  • Sanitization: The skill employs a 'Step 4: Answer post-check' to ensure responses remain in character and do not perform unauthorized meta-analysis.\n- [SAFE]: All external references, such as WeChat IDs (e.g., sjxg1114, 289736234) and GitHub links for the creation tool, are consistent with the professional branding of the skill's persona and do not represent malicious exfiltration endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 05:35 PM
Security Audit — agent-trust-hub — shaoniannu-perspective