etsy-tony-full-design-skus
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No attempts to override system behavior or bypass safety guardrails were identified. The instructions focus on structured product development workflows and logical modes.
- [DATA_EXPOSURE]: No hardcoded secrets, API keys, or sensitive local file paths (e.g., .env, .ssh) were found in the skill files. Secret management instructions recommend safe practices like employee-provided evidence.
- [OBFUSCATION]: The skill uses clear text in English and Chinese. No multi-layer encoding, hidden zero-width characters, or homoglyph-based URL spoofing were detected.
- [REMOTE_CODE_EXECUTION]: The skill does not perform external downloads or execute remote scripts. It relies on internal markdown references for its logic and platform-provided tools for image generation.
- [DYNAMIC_EXECUTION]: No usage of
eval(),exec(), or runtime code generation from untrusted sources was identified. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted competitor data (links and descriptions). It mitigates injection risks through specific 'Originality Gates' and a 'Five Highest Principles' framework (P5) that explicitly prohibits the reproduction of distinctive protected expressions.
Audit Metadata