laohan-xiazai

Fail

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructs the installation of a Root CA certificate (SunnyRoot.cer) into the system's trusted root store and running the wx_video_download tool with sudo (macOS) or Administrator (Windows) privileges. This configuration is explicitly designed to perform Man-in-the-Middle (MITM) interception and decryption of HTTPS traffic from the WeChat client to facilitate video downloads.\n- [REMOTE_CODE_EXECUTION]: The skill encourages downloading and executing binary installers (.dmg and .exe) from the author's GitHub release page (hanzhcn/laohan-skills). Additionally, it utilizes npx skills update to dynamically fetch and execute remote skill definitions for the opencli ecosystem.\n- [COMMAND_EXECUTION]: The instructions rely on numerous shell commands for global package management (npm update -g @jackwener/opencli), daemon control (opencli daemon restart), and media processing workflows using ffmpeg and yt-dlp.\n- [DYNAMIC_EXECUTION]: The skill generates and executes Python scripts at runtime using shell heredocs (python3 << 'PYEOF') to automate multi-step download and transcription tasks.\n- [EXTERNAL_DOWNLOADS]: The skill communicates with several external third-party services and APIs, such as tikwm.com for TikTok content and siliconflow.cn for audio transcription, which involves sending media files to remote endpoints.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface as it ingests untrusted data from URLs across multiple social media platforms. It possesses extensive capabilities including shell command execution, file writing, and network operations (Capability inventory: curl, ffmpeg, npx, python, sudo). There are no explicit boundary markers or sanitization steps documented to prevent malicious instructions embedded in the processed web content from influencing the agent's behavior (Ingestion points: SKILL.md, douyin.md; Boundary markers: absent; Sanitization: absent).
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 27, 2026, 02:23 AM
Security Audit — agent-trust-hub — laohan-xiazai