lexiang-knowledge-base

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill implements extensive defensive instructions to prevent accidental or malicious behavior. The SKILL.md defines 'Writing Operation Safety Rules' that prohibit the agent from guessing targets or acting without explicit user-provided identifiers. Additionally, while the skill processes external content from local files (Category 8 surface), it employs boundary markers and transforms content into a proprietary block structure, effectively mitigating indirect injection risks.- [DATA_EXFILTRATION]: Authentication tokens are handled according to security best practices, with instructions to use HTTP Authorization headers to avoid exposure in URL logs. Network activity is confined to vendor-controlled domains required for platform interaction.- [COMMAND_EXECUTION]: The skill includes TypeScript and Python scripts to handle advanced tasks such as incremental folder syncing and parallel file uploads. These scripts are provided within the skill package, are clearly documented for the user, and perform tasks consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 12:16 AM