zmm-topic
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents workflows that invoke local Python scripts with placeholder parameters derived from user text inputs (e.g.,
python3 {vault}/07-脚本与工具/surface_candidates.py --kw "{关键词}" --top 15inSKILL.md). If implemented dynamically without escaping, this introduces a command execution or argument injection risk. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided concepts, keywords, and video topics to diagnose or generate topic pipelines, presenting an indirect prompt injection surface.
- Ingestion points:
SKILL.mdandreferences/问题探寻与共鸣.mdingest external topic suggestions, keywords, and user queries. - Boundary markers: Absent; there are no clear delimiters or boundary enforcement tags isolating untrusted text within the prompt context.
- Capability inventory: Invokes local automation tools and logs content choices into the pipeline (
06-选题装配/选题管道.md). - Sanitization: Lacks explicit validation or sanitization routines for raw input values interpolated into tool execution strings.
Audit Metadata