skills/orziz/odai/ribao/Gen Agent Trust Hub

ribao

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest external data sources such as work materials, task records, and system logs to generate reports. This processing of untrusted data represents an indirect prompt injection surface.
  • Ingestion points: The skill reads user-provided materials, task statuses, and work records (SKILL.md, "收集事实" section).
  • Boundary markers: There are no explicit instructions for the agent to ignore or delimit embedded instructions within the ingested work records.
  • Capability inventory: The skill is limited to generating text for reports ("形成正文"); no command execution or network tools are defined in the provided files.
  • Sanitization: No sanitization or validation of the input data is described in the instructions.
  • [NO_CODE]: The skill consists entirely of markdown instructions and YAML configuration for the AI agent, with no executable scripts, binaries, or package dependencies included.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 03:23 PM
Security Audit — agent-trust-hub — ribao