ip-evaluator
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection. 1. Ingestion points: The skill is instructed to gather and summarize IP network information ('梳理IP网络信息'). 2. Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the prompt. 3. Capability inventory: The skill has 'allowed-tools: []' in frontmatter, restricting its access to external tools, which limits the potential impact of an injection. 4. Sanitization: No evidence of input validation or sanitization is present.
- [SAFE]: The skill primarily consists of descriptive prompts and scoring frameworks. It does not include any scripts, binary executables, or network operations that would pose a direct security threat.
Audit Metadata