create-ex

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface
  • Ingestion points: The skill ingests untrusted data from external sources including WeChat chat logs, QQ messages, and social media screenshots via scripts like wechat_parser.py and social_parser.py (referenced in SKILL.md).
  • Boundary markers: The prompt templates in prompts/memory_analyzer.md and prompts/persona_analyzer.md lack explicit delimiters or instructions to treat ingested data as inert text, making the agent susceptible to instructions embedded within the chat logs.
  • Capability inventory: The skill has access to Bash, Write, and Edit tools, allowing for file system modifications and shell command execution based on analyzed content.
  • Sanitization: There is no visible sanitization or filtering logic to neutralize potential malicious prompts within the processed text files.
  • [COMMAND_EXECUTION]: Local Script Execution
  • The skill utilizes the Bash tool to run local Python scripts included in the package (wechat_parser.py, qq_parser.py, social_parser.py, photo_analyzer.py, skill_writer.py, version_manager.py). These scripts are used for data processing and version control. Analysis of the source code confirms they perform local operations and do not initiate unauthorized network connections.
  • [DATA_EXFILTRATION]: Sensitive Data Handling
  • The skill is designed to process highly sensitive personal information, including private conversations and photos containing EXIF metadata (GPS coordinates). While the skill claims local storage, the content of these files is necessarily shared with the LLM provider during the analysis and persona generation phases.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 09:18 PM
Security Audit — agent-trust-hub — create-ex