content-extract
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process content from arbitrary external URLs (including WeChat, Zhihu, and GitHub). This represents an attack surface where malicious instructions embedded in a fetched webpage could attempt to influence the agent's subsequent behavior.
- Ingestion points: User-provided
urlparameter inscripts/content_extract.py, output from theweb_fetchtool, and responses from the GitHub and MinerU APIs. - Boundary markers: The skill defines a structured "Result Contract" JSON format in
SKILL.mdto help separate extracted content from the agent's instructions. - Capability inventory: The skill uses
subprocess.runto call an internal parsing script and utilizes network-capable functionality likeweb_fetchand the GitHub API. - Sanitization: The implementation in
scripts/content_extract.pyextracts data from structured JSON responses but does not explicitly sanitize the final markdown content for embedded prompt instructions. - [COMMAND_EXECUTION]: The script
scripts/content_extract.pymanages the execution of a local MinerU parsing tool via thesubprocessmodule. - Evidence: The script passes the user-supplied
urlas an argument to the internal script/home/node/.openclaw/workspace/skills/mineru-extract/scripts/mineru_parse_documents.py. Although it uses a list-based argument structure to mitigate shell injection risks, it still involves running external processes with user-controlled parameters.
Audit Metadata