kimi-use

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes data from third-party Kimi plugins (such as SEC, IMF, and financial databases) through GUI automation (Accessibility Tree and screenshots) and local sandbox files, creating an attack surface for indirect prompt injection from malicious external data. Ingestion points: Kimi.app GUI output and files located in ~/Library/Application Support/kimi-desktop/. Boundary markers: The instructions lack rigid delimiters for ingested data, relying instead on honesty-based prompt instructions to separate source data from model reasoning. Capability inventory: Full GUI control via computer-use MCP, shell command execution (find, xargs, pbpaste), and file system access. Sanitization: The skill mandates a verification discipline, requiring the agent to cross-reference Chinese proper names and numerical values against independent authoritative sources like official websites or specific CLI tools.
  • [COMMAND_EXECUTION]: The skill uses shell commands to manage data retrieval and verification, including accessing the system clipboard via pbpaste and searching application-specific directories for generated data files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 06:35 PM
Security Audit — agent-trust-hub — kimi-use