huashu-research
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions define a legitimate workflow for information gathering and knowledge management. No obfuscation, unauthorized command execution, or sensitive data exfiltration patterns were identified.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted data from external web searches and writes it to the local file system. 1. Ingestion points: External data enters the context via the WebSearch tool referenced in the execution flow. 2. Boundary markers: The skill uses structured Markdown headers (e.g., '发现', '来源列表') to delimit content, providing structural separation. 3. Capability inventory: The skill employs file-writing capabilities to store research data in the _knowledge_base/ directory. 4. Sanitization: There is no explicit logic described for sanitizing or filtering instructions that might be embedded in the retrieved web content.
Audit Metadata