huashu-info-search
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to perform multi-channel searches across external tech media and community platforms (e.g., TechCrunch, Reddit, Hacker News) and save the information to local directories, presenting an indirect prompt injection attack surface.
- Ingestion Points: Untrusted third-party content retrieved via search strategies mentioned in
SKILL.md(e.g., tech news, community forums, and blog posts). - Boundary Markers: Absent. The instructions do not define text isolation delimiters or explicit directives to ignore commands embedded in the search results.
- Capability Inventory: File creation and write operations targeting
/公众号写作/_knowledge_base/and/视频创作/_knowledge_base/templates. - Sanitization: Absent. Content is processed and saved in Markdown format without structured schemas, escaping logic, or input filtering.
Audit Metadata