skills/xyaz1313/xyskill/xy-recut/Gen Agent Trust Hub

xy-recut

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines clear logic for video transcript restructuring and cleanup. It focuses entirely on textual analysis and markdown output without requesting access to dangerous system tools or external network resources. References to shared configuration files (_shared/voice-profile.md, _shared/chinese-writing.md) and related skills (xy-clip, xy-atomize) are consistent with the vendor's modular architecture.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes user-provided video transcripts.
  • Ingestion points: Transcripts with timecodes provided by the user (Workflow Step 1).
  • Boundary markers: No specific delimiters are defined for the input content; however, the output is restricted to a structured markdown table.
  • Capability inventory: Analysis and generation of text/markdown. No access to subprocesses, network operations, or file-writing tools.
  • Sanitization: The skill explicitly enforces a 'zero-word-addition' policy and prohibits rewriting or adding new logic (Core Constraints #1 & #2), which prevents the agent from executing instructions potentially embedded in the input transcript data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:59 AM
Security Audit — agent-trust-hub — xy-recut