create-ex
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface
- Ingestion points: The skill ingests untrusted data from external sources including WeChat chat logs, QQ messages, and social media screenshots via scripts like
wechat_parser.pyandsocial_parser.py(referenced inSKILL.md). - Boundary markers: The prompt templates in
prompts/memory_analyzer.mdandprompts/persona_analyzer.mdlack explicit delimiters or instructions to treat ingested data as inert text, making the agent susceptible to instructions embedded within the chat logs. - Capability inventory: The skill has access to
Bash,Write, andEdittools, allowing for file system modifications and shell command execution based on analyzed content. - Sanitization: There is no visible sanitization or filtering logic to neutralize potential malicious prompts within the processed text files.
- [COMMAND_EXECUTION]: Local Script Execution
- The skill utilizes the
Bashtool to run local Python scripts included in the package (wechat_parser.py,qq_parser.py,social_parser.py,photo_analyzer.py,skill_writer.py,version_manager.py). These scripts are used for data processing and version control. Analysis of the source code confirms they perform local operations and do not initiate unauthorized network connections. - [DATA_EXFILTRATION]: Sensitive Data Handling
- The skill is designed to process highly sensitive personal information, including private conversations and photos containing EXIF metadata (GPS coordinates). While the skill claims local storage, the content of these files is necessarily shared with the LLM provider during the analysis and persona generation phases.
Audit Metadata