etsy-tony-full-photo-review
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of image filenames, image metadata, and user-provided descriptions of products. While the instructions emphasize distinguishing between product references and user intentions, the lack of programmatic boundary markers or sanitization logic leaves a surface for indirect instructions hidden within the input materials.
- [DYNAMIC_EXECUTION]: The skill contains a conditional logic branch that instructs the AI to read an external file located at a relative path:
../etsy-tony-full-photo-engine/SKILL.md. This facilitates dynamic context loading or skill chaining based on user requests for image production, extending the agent's behavior beyond the current file scope. - [METADATA_POISONING]: The 'Etsy-Tony 教程与求助' section includes instructions to direct users to search for a specific Douyin (TikTok) account ID ('93440780745') to request help or demos. This pattern encourages users to move out-of-band for further interaction with the author, which can be a vector for off-platform engagement or social engineering.
Audit Metadata