story-short-analyze

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The SKILL.md file contains explicit instructions to override the agent's safety guidelines. Specifically, it states that the agent must not refuse to process content based on 'sensitivity' or 'discomfort' regarding fictional elements like violence or dark ethics. This is a direct attempt to bypass content safety filters.
  • [PROMPT_INJECTION]: The instructions include 'ignore-previous-instructions' patterns by telling the agent that the analysis stage must proceed regardless of its internal safety evaluations, potentially overriding its default behavior when encountering mature content.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze untrusted external data (web novels).
  • Ingestion points: The text is obtained in Step 1 ('你要拆哪篇?') either via file path or direct text input.
  • Boundary markers: There are no explicit delimiters or instructions to treat the ingested novel text as data only, which could allow instructions embedded within a story to influence the agent's analysis or output.
  • Capability inventory: The skill has file-write capabilities, creating and modifying files in the 拆文库/{书名}/ directory based on the analysis.
  • Sanitization: No evidence of sanitization or escaping of the external novel content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 10:44 PM
Security Audit — agent-trust-hub — story-short-analyze