huashu-info-search

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to perform multi-channel searches across external tech media and community platforms (e.g., TechCrunch, Reddit, Hacker News) and save the information to local directories, presenting an indirect prompt injection attack surface.
  • Ingestion Points: Untrusted third-party content retrieved via search strategies mentioned in SKILL.md (e.g., tech news, community forums, and blog posts).
  • Boundary Markers: Absent. The instructions do not define text isolation delimiters or explicit directives to ignore commands embedded in the search results.
  • Capability Inventory: File creation and write operations targeting /公众号写作/_knowledge_base/ and /视频创作/_knowledge_base/ templates.
  • Sanitization: Absent. Content is processed and saved in Markdown format without structured schemas, escaping logic, or input filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:55 AM
Security Audit — agent-trust-hub — huashu-info-search