qiaomu-opencli-oneshot

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to navigate to and process data from external URLs via browser_navigate and browser_network_requests. This creates an ingestion surface for untrusted data that could contain malicious instructions.
  • Ingestion points: Browser navigation to arbitrary URLs (Step 1) and network request capture.
  • Boundary markers: None specified in the instructions.
  • Capability inventory: browser_navigate, browser_network_requests, browser_evaluate (JS execution), and file writing for adapter generation.
  • Sanitization: None provided for the data extracted from network responses.
  • [DYNAMIC_EXECUTION]: The templates use page.evaluate to execute dynamic JavaScript code within the browser context. This is used to simulate fetch requests and extract data from the page DOM at runtime.
  • [EXTERNAL_DOWNLOADS]: The skill requires the @jackwener/opencli package, which is an external dependency used to build the CLI adapters.
  • [CREDENTIALS_UNSAFE]: One of the TypeScript templates (TS — Header) includes a hardcoded Bearer token. Although this appears to be a commonly known public token for guest access, hardcoding authentication tokens in templates is a sensitive practice.
  • [DATA_EXFILTRATION]: The skill demonstrates how to extract sensitive authentication data from the browser environment, specifically accessing document.cookie and X-Csrf-Token to facilitate authenticated API requests.
  • [COMMAND_EXECUTION]: The skill provides instructions for the user or agent to run shell commands such as npm run build and opencli for testing and registration purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:04 PM
Security Audit — agent-trust-hub — qiaomu-opencli-oneshot