baoyu-xhs-images

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill demonstrates security best practices by implementing mandatory confirmation checkpoints at Step 2 and Step 4, ensuring the user reviews the content analysis and the selected outline strategy before image generation proceeds.
  • [COMMAND_EXECUTION]: Employs standard shell commands for environment detection and project management. Specifically, it uses test to check for the existence of configuration files (EXTEND.md) in local or home directories and uses basic filesystem operations to save source content and generated prompts. These actions are limited to the skill's own functional directories.
  • [PROMPT_INJECTION]: While the skill ingests untrusted user content for analysis and image generation, the risk of indirect prompt injection is mitigated by the structured prompt assembly process and the narrow capability of the downstream tool (image generation). The skill includes explicit instructions to the agent to avoid unauthorized tools and maintain adherence to the provided visual specifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 01:30 AM
Security Audit — agent-trust-hub — baoyu-xhs-images