juejin-article-to-markdown

Fail

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches article data from the Juejin developer platform (juejin.cn) and utilizes mermaid.ink for diagram generation. These are well-known services directly related to the skill's purpose.- [COMMAND_EXECUTION]: The skill provides logic templates in Python and JavaScript for the agent to extract diagrams from the page's internal state (window.NUXT), which involves processing JavaScript strings at runtime.- [PROMPT_INJECTION]: As the skill ingests and processes untrusted data from external articles, it is susceptible to indirect prompt injection where an attacker could craft a Juejin article containing hidden instructions intended to influence the agent's behavior during the conversion process.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — juejin-article-to-markdown