dby-rewrite

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a Python script scripts/rewrite.py that is used to retrieve platform-specific rules from local markdown files.- [COMMAND_EXECUTION]: The documentation provides templates for the agent to execute shell commands using other local vendor scripts (dby-banned-words and dby-api) for content validation and draft management.- [INDIRECT_PROMPT_INJECTION]: A vulnerability surface is present where the skill processes untrusted user data. Evidence chain: 1. Ingestion point: User-provided text (文案) mentioned in SKILL.md. 2. Boundary markers: None. 3. Capability inventory: Execution of external scripts via python3 and node as instructed in SKILL.md and references/draft/draft-changes.md. 4. Sanitization: Absent. The agent is directed to interpolate user content directly into shell command arguments, which could allow for command injection if the input is malicious.- [SAFE]: The skill operates entirely offline as claimed, with no network-enabled tools, external downloads, or credential requirements found in the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:50 PM
Security Audit — agent-trust-hub — dby-rewrite