skills/hk-hub/agentskills/qcc-company/Gen Agent Trust Hub

qcc-company

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill connects to a remote MCP server at https://agent.qcc.com. This domain belongs to Qichacha, a well-known and legitimate service for corporate data in China, and the connection is necessary for the skill's primary function.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a third-party source, creating a potential attack surface. Ingestion points: Data is received from the Qichacha API via the mcp.json configuration. Boundary markers: The instructions do not define specific delimiters for the API responses. Capability inventory: The skill is limited to read-only corporate lookups and does not have access to file-write or shell-execution tools. Sanitization: No specific sanitization of external data is defined. The risk is considered safe due to the lack of exploitable capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — qcc-company