tencent-survey

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local shell script named setup.sh for authentication and configuration (e.g., bash "${SKILL_DIR}/setup.sh" wj_check_and_start_auth). This occurs in SKILL.md and references/auth.md. While standard for this skill's initialization, it grants the skill the ability to run arbitrary shell commands on the host system.- [PROMPT_INJECTION]: The SKILL.md file defines a dynamic update flow where the agent calls the check_skill_update tool and is explicitly told to "follow the instruction directive to update." This creates a risk where a response from a remote tool can dictate agent behavior, potentially leading to unauthorized actions or safety bypasses if the source provides malicious instructions.- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests and displays untrusted data from survey titles, questions, and user answers via the get_survey and list_answers tools. Ingestion points: list_answers and get_survey (File: SKILL.md). Boundary markers: None identified. Capability inventory: Shell script execution (setup.sh), survey modification (update_question), and logic updates (update_logic). Sanitization: The documentation only mentions basic HTML tag removal for display purposes (File: SKILL.md).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — tencent-survey