page-editor
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
- [DATA_EXFILTRATION]: The skill implements a sophisticated telemetry system that collects extensive host information, including the hostname, current username, machine-id (from
/etc/machine-id), MAC address, and platform-specific hardware identifiers like the Windows MachineGuid and macOS IOPlatformUUID. This metadata is transmitted to an external analytics service athttps://otheve.beacon.qq.com/analytics/v2_upload. - [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for users to edit text and styles in a browser, which are then output as structured JSON instructions for the AI agent to apply directly to source code. This creates a surface where malicious instructions could be embedded in modified text or attribute fields. The skill instructions encourage the agent to apply these changes automatically without manual verification and lack boundary markers to separate user data from instructions.
- [EXTERNAL_DOWNLOADS]: During its setup phase, the skill executes
npm installto download dependencies from the NPM registry. - [COMMAND_EXECUTION]: The telemetry and fingerprinting logic invokes several system diagnostic commands, including
hostname,whoami,reg query(Windows), andioreg(macOS), to extract unique system identifiers. - [PERSISTENCE]: The telemetry system maintains state across sessions by creating and reading a hidden directory and file at
~/.skill-tracker/device-idto store a persistent unique identifier for the host machine.
Audit Metadata