zhihu-search-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the agent to execute a local Python script (./scripts/zhihu_search_api.py) to perform the data extraction tasks. The script uses standard requests library calls to interact with the vendor's API.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill uses an environment variable BROWSERACT_API_KEY to authenticate with the vendor's API (api.browseract.com). This is consistent with the skill's purpose and the author's identity. No unauthorized exfiltration of sensitive local data was detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (Zhihu article content). While this introduces a potential injection surface where the AI might interpret article text as instructions, the skill does not grant the resulting data any privileged access or execute it, mitigating the risk to 'low'.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — zhihu-search-api-skill