hundun

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local Shell, PowerShell, and Python scripts to perform operations like configuration management, API requests, and content processing. These scripts are contained within the skill directory and perform administrative and data-retrieval tasks.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the vendor's official API at hddrapi.hundun.cn and tools.hundun.cn to fetch course data. It also downloads course transcripts from encrypted URLs provided by the API; these are decrypted locally using a hardcoded AES key and standard Python libraries. All external communication is confined to verified vendor infrastructure.
  • [SAFE]: The skill demonstrates secure handling of sensitive data by instructing users on proper API key setup and using filesystem permissions (chmod 600) to protect the local configuration file. No evidence of prompt injection, data exfiltration, or malicious obfuscation was found during the analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 06:31 PM
Security Audit — agent-trust-hub — hundun