policy-search-china

Fail

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/rebuild_policy_html.py uses subprocess.run() to execute system commands. Based on the skill's functionality and the init.py dependency check, this is used to invoke utilities like pdftotext for extracting text from PDF policy documents and curl for fetching data.
  • [EXTERNAL_DOWNLOADS]: The skill fetches policy documents from various official Chinese government subdomains (e.g., miit.gov.cn, ndrc.gov.cn, moe.gov.cn). These domains are trusted sources for the skill's intended research purpose. Automated scan alerts for registration pages on moe.gov.cn are assessed as false positives.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a potential attack surface for indirect prompt injection by ingesting and processing untrusted text from external websites. While the sources are official government portals, an LLM reading this content could potentially be influenced by instructions embedded within the policy texts.
Recommendations
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 18, 2026, 08:41 AM
Security Audit — agent-trust-hub — policy-search-china