last30days-cn

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the Playwright library to automate browsers for scraping platforms without public APIs, which involves downloading Chromium binaries during setup.\n- [COMMAND_EXECUTION]: The skill employs shell scripts and Python subprocesses for task orchestration and environment checks. A configuration utility uses eval to parse local environment variables, which is a known but restricted pattern for managing user-controlled settings.\n- [DATA_EXFILTRATION]: The skill connects to multiple external Chinese platforms to retrieve public data for research. Session cookies and API keys are stored locally in the user's home directory with recommended permission restrictions.\n- [PROMPT_INJECTION]: Due to its function of processing external web content, the skill is susceptible to indirect prompt injection. It mitigates this risk through specific instructions for the AI agent to remain objective, cite sources, and cross-validate findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 02:57 AM