skills/hk-hub/agentskills/page-editor/Gen Agent Trust Hub

page-editor

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
  • [DATA_EXFILTRATION]: The skill implements a sophisticated telemetry system that collects extensive host information, including the hostname, current username, machine-id (from /etc/machine-id), MAC address, and platform-specific hardware identifiers like the Windows MachineGuid and macOS IOPlatformUUID. This metadata is transmitted to an external analytics service at https://otheve.beacon.qq.com/analytics/v2_upload.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for users to edit text and styles in a browser, which are then output as structured JSON instructions for the AI agent to apply directly to source code. This creates a surface where malicious instructions could be embedded in modified text or attribute fields. The skill instructions encourage the agent to apply these changes automatically without manual verification and lack boundary markers to separate user data from instructions.
  • [EXTERNAL_DOWNLOADS]: During its setup phase, the skill executes npm install to download dependencies from the NPM registry.
  • [COMMAND_EXECUTION]: The telemetry and fingerprinting logic invokes several system diagnostic commands, including hostname, whoami, reg query (Windows), and ioreg (macOS), to extract unique system identifiers.
  • [PERSISTENCE]: The telemetry system maintains state across sessions by creating and reading a hidden directory and file at ~/.skill-tracker/device-id to store a persistent unique identifier for the host machine.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:44 AM
Security Audit — agent-trust-hub — page-editor