wenqu-library

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the installation and execution of external CLI tools, open-websearch and crawl4ai, to enhance its searching and crawling capabilities. These tools are installed via standard package managers (npm, pip, or uv). The skill incorporates a robust safety protocol requiring explicit user authorization before any installation occurs, and it provides a fallback mechanism to use the agent's native tools if the external ones are not authorized or fail to install.
  • [COMMAND_EXECUTION]: The skill performs shell commands to interact with the installed CLI tools for web searching (open-websearch search) and content downloading (crwl). These commands include various parameters for output formatting, depth of crawling, and site-specific handling (e.g., specialized headers for WeChat Official Accounts). The instructions provide clear boundaries for these commands, such as mandatory page limits for deep crawling and a ban on launching persistent background daemons.
  • [PROMPT_INJECTION]: The skill is designed to ingest and process content from external web sources (articles, documentation, and technical blogs) to create summaries and indices. This introduces a surface for indirect prompt injection, where malicious instructions hidden within processed web pages could potentially influence the agent's output. The skill mitigates this by instructing the agent to perform its own summarization and fact-checking within its context rather than relying on external tool-provided analysis, and by maintaining strict records of material provenance.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 08:32 AM
Security Audit — agent-trust-hub — wenqu-library