skills/yikzero/skills/humanize-zh/Gen Agent Trust Hub

humanize-zh

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists solely of Markdown documentation (SKILL.md, references/*.md) and a YAML configuration. There are no executable scripts (Python, JavaScript, Shell) included in the package.
  • [DATA_EXPOSURE]: No hardcoded credentials, API keys, or access to sensitive system paths (e.g., .ssh, .aws, .env) were found. The skill operates entirely on text provided by the user within the conversation context.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns or dynamic script loading were detected. The npx yskill command mentioned in the README is an external installation instruction for the platform CLI and not an internal skill dependency or script.
  • [DATA_EXFILTRATION]: No network-capable tools or commands (e.g., curl, wget, fetch) are present. The skill does not attempt to send data to external domains.
  • [PROMPT_INJECTION]: The instructions are focused on text editing and do not contain patterns attempting to bypass safety filters or override system-level instructions.
  • [SAFE]: The skill includes 'Honesty Redlines' (SKILL.md) that explicitly prohibit the AI from fabricating first-person experiences, data, or citations, which serves as a safety guardrail against hallucinations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 08:18 AM
Security Audit — agent-trust-hub — humanize-zh