openydt-shared
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill includes proactive instructions that warn against treating data fields from the platform as commands, which provides defense against indirect prompt injection attacks.
- [DATA_EXPOSURE]: Accesses and manages sensitive configuration paths such as
~/.config/openydt-cli/config.json, but enforces restricted file permissions (0600) and secret masking to protect user credentials. - [DATA_EXFILTRATION]: Network operations are directed exclusively to official service domains (
yidianting.com.cn,yidianting.xin) for intended API functions, with no unauthorized data transmission detected. - [EXTERNAL_DOWNLOADS]: Documents a standard tool update command (
openydt update) used to maintain the CLI and its associated business skills through official package registries.
Audit Metadata