baoyu-infographic

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted content from user-provided files (Step 1.2) and is explicitly instructed to preserve all data verbatim. This content is interpolated into the 'prompts/infographic.md' file via the 'references/base-prompt.md' template without robust boundary markers or sanitization, potentially allowing an attacker to influence the downstream image generation process. 1. Ingestion points: The skill reads external content from a file path or user paste in Step 1.2. 2. Boundary markers: The prompt template does not use delimiters for the {{CONTENT}} interpolation. 3. Capability inventory: The skill has file-write access and executes bash commands. 4. Sanitization: No sanitization is performed due to the verbatim data rule.
  • [COMMAND_EXECUTION]: During the setup phase (Step 1.1), the skill instructs the agent to execute bash commands ('test -f') to check for the existence of configuration files ('EXTEND.md') in project-local and user-home directories.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:09 AM