etsy-tony-full-design-skus

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No attempts to override system behavior or bypass safety guardrails were identified. The instructions focus on structured product development workflows and logical modes.
  • [DATA_EXPOSURE]: No hardcoded secrets, API keys, or sensitive local file paths (e.g., .env, .ssh) were found in the skill files. Secret management instructions recommend safe practices like employee-provided evidence.
  • [OBFUSCATION]: The skill uses clear text in English and Chinese. No multi-layer encoding, hidden zero-width characters, or homoglyph-based URL spoofing were detected.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform external downloads or execute remote scripts. It relies on internal markdown references for its logic and platform-provided tools for image generation.
  • [DYNAMIC_EXECUTION]: No usage of eval(), exec(), or runtime code generation from untrusted sources was identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted competitor data (links and descriptions). It mitigates injection risks through specific 'Originality Gates' and a 'Five Highest Principles' framework (P5) that explicitly prohibits the reproduction of distinctive protected expressions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:46 AM
Security Audit — agent-trust-hub — etsy-tony-full-design-skus