tianyancha-cn
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Comprehensive analysis of the provided documentation and metadata files found no evidence of malicious code, obfuscation, or unauthorized data access patterns.
- [EXTERNAL_DOWNLOADS]: The skill documents integration with legitimate business intelligence APIs (Tianyancha and Qichacha) and suggests the use of the 'tianyancha' Python package. These are standard resources for the skill's stated purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting corporate data from external APIs into the agent context.
- Ingestion points: Data retrieved from
open.api.tianyancha.comandapi.qichacha.com. - Boundary markers: None present in the provided documentation examples.
- Capability inventory: No executable scripts or custom tools provided with the skill; capabilities depend on the agent's pre-existing toolset (e.g., shell).
- Sanitization: No sanitization or validation methods are described for the external API payloads.
Audit Metadata