create-master
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The framework implements a RAG system that ingests external data from the FoJin API (fojin.app), creating a surface for indirect prompt injection where malicious instructions could be embedded in retrieved text. The skill implements robust mitigations for this:
- Ingestion points: Data enters the agent context through
tools/rag_query.py,tools/sutra_collector.py, andtools/fojin_bridge.py. - Boundary markers: The skill uses explicit delimiters such as
<<<FOJIN_DATA>>>and===== FOJIN 检索数据 ... =====to wrap all external data. - Sanitization: Scripts like
master_builder.pyandrag_query.pyimplement a 'loop-until-stable' scrubbing algorithm that recursively removes forged boundary markers and strips Unicode control/bi-directional/zero-width characters to prevent instruction leakage. - Capability inventory: The skill possesses file-write capabilities for generating master personas (
tools/skill_writer.py) and executes internal Python/Node.js scripts for validation and installation management. - [COMMAND_EXECUTION]: The skill uses Node.js and Python scripts to manage persona installation and validation. All inputs that flow into shell commands or file system operations are strictly validated against allow-lists (
isSafeNameand_SAFE_MASTERregex) to prevent path traversal and command injection. - [REMOTE_CODE_EXECUTION]: While the skill communicates with the FoJin API (
fojin.app) for text retrieval, it does not download or execute remote code (e.g., viacurl | bash). It uses a well-defined REST API for data retrieval only. - [PROMPT_INJECTION]: The system uses a multi-layered 'HARD-GATE' approach in its system instructions, explicitly prohibiting the AI from making doctrinal claims without real citations or confirming spiritual attainments, which serves as a defensive measure against adversarial user input.
Audit Metadata