tianyancha-cn

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Comprehensive analysis of the provided documentation and metadata files found no evidence of malicious code, obfuscation, or unauthorized data access patterns.
  • [EXTERNAL_DOWNLOADS]: The skill documents integration with legitimate business intelligence APIs (Tianyancha and Qichacha) and suggests the use of the 'tianyancha' Python package. These are standard resources for the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting corporate data from external APIs into the agent context.
  • Ingestion points: Data retrieved from open.api.tianyancha.com and api.qichacha.com.
  • Boundary markers: None present in the provided documentation examples.
  • Capability inventory: No executable scripts or custom tools provided with the skill; capabilities depend on the agent's pre-existing toolset (e.g., shell).
  • Sanitization: No sanitization or validation methods are described for the external API payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 03:32 AM
Security Audit — agent-trust-hub — tianyancha-cn