content-extract

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process content from arbitrary external URLs (including WeChat, Zhihu, and GitHub). This represents an attack surface where malicious instructions embedded in a fetched webpage could attempt to influence the agent's subsequent behavior.
  • Ingestion points: User-provided url parameter in scripts/content_extract.py, output from the web_fetch tool, and responses from the GitHub and MinerU APIs.
  • Boundary markers: The skill defines a structured "Result Contract" JSON format in SKILL.md to help separate extracted content from the agent's instructions.
  • Capability inventory: The skill uses subprocess.run to call an internal parsing script and utilizes network-capable functionality like web_fetch and the GitHub API.
  • Sanitization: The implementation in scripts/content_extract.py extracts data from structured JSON responses but does not explicitly sanitize the final markdown content for embedded prompt instructions.
  • [COMMAND_EXECUTION]: The script scripts/content_extract.py manages the execution of a local MinerU parsing tool via the subprocess module.
  • Evidence: The script passes the user-supplied url as an argument to the internal script /home/node/.openclaw/workspace/skills/mineru-extract/scripts/mineru_parse_documents.py. Although it uses a list-based argument structure to mitigate shell injection risks, it still involves running external processes with user-controlled parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 01:43 PM