zengguofan-perspective

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The instructions require the agent to display a safety disclaimer (explaining the persona is based on literature) only once during the initial interaction and suppress it in subsequent turns.
  • [PROMPT_INJECTION]: The skill mandates strict character adherence as "Zeng Guofan," forbidding the agent from engaging in meta-analysis or departing from the persona unless the user specifically requests to "exit" the role.
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection by processing untrusted user inputs (questions about discipline, leadership, or personal failure) to provide analysis.
  • Ingestion points: User questions and descriptions of life situations processed in the 'Answer Workflow' in SKILL.md.
  • Boundary markers: The skill does not use delimiters (like triple quotes or XML tags) or explicit instructions to ignore embedded commands in user input.
  • Capability inventory: The agent performs read operations on local files 'references/research.md' and 'examples/demo-conversation.md'.
  • Sanitization: No validation or escaping of user-provided content is implemented before it is processed by the persona framework.
  • [EXTERNAL_DOWNLOADS]: The README provides an installation command 'npx skills add nuwa-skills/zengguofan-skill' which downloads content from an external repository associated with the author.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 05:19 AM
Security Audit — agent-trust-hub — zengguofan-perspective