laozi-perspective
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed entirely of markdown documentation and role-playing instructions. No executable code (Python, JavaScript, shell scripts) or configuration files that could facilitate malicious behavior were found.
- [PROMPT_INJECTION]: The skill contains instructions for the agent to adopt a specific persona ('Laozi'). These instructions define a character-based cognitive framework and do not attempt to bypass safety filters, extract system prompts, or override fundamental safety guidelines. The role-play is aligned with the skill's stated purpose.
- [EXTERNAL_DOWNLOADS]: While the README mentions installation via
npx, this is a standard platform command for skill management. The skill itself does not perform any remote code execution, piped downloads, or runtime package installations. - [DATA_EXFILTRATION]: No patterns for accessing sensitive files (such as
.ssh,.aws, or.env) or exfiltrating data to external domains were detected. The skill operates entirely within the conversational context provided by the user. - [COMMAND_EXECUTION]: The skill does not contain any shell commands, subprocess calls, or dynamic context injection patterns (e.g.,
!commandsyntax).
Audit Metadata