qcc-company
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill connects to a remote MCP server at
https://agent.qcc.com. This domain belongs to Qichacha, a well-known and legitimate service for corporate data in China, and the connection is necessary for the skill's primary function. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a third-party source, creating a potential attack surface. Ingestion points: Data is received from the Qichacha API via the
mcp.jsonconfiguration. Boundary markers: The instructions do not define specific delimiters for the API responses. Capability inventory: The skill is limited to read-only corporate lookups and does not have access to file-write or shell-execution tools. Sanitization: No specific sanitization of external data is defined. The risk is considered safe due to the lack of exploitable capabilities.
Audit Metadata