qiaomu-opencli-oneshot
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to navigate to and process data from external URLs via
browser_navigateandbrowser_network_requests. This creates an ingestion surface for untrusted data that could contain malicious instructions. - Ingestion points: Browser navigation to arbitrary URLs (Step 1) and network request capture.
- Boundary markers: None specified in the instructions.
- Capability inventory:
browser_navigate,browser_network_requests,browser_evaluate(JS execution), and file writing for adapter generation. - Sanitization: None provided for the data extracted from network responses.
- [DYNAMIC_EXECUTION]: The templates use
page.evaluateto execute dynamic JavaScript code within the browser context. This is used to simulatefetchrequests and extract data from the page DOM at runtime. - [EXTERNAL_DOWNLOADS]: The skill requires the
@jackwener/openclipackage, which is an external dependency used to build the CLI adapters. - [CREDENTIALS_UNSAFE]: One of the TypeScript templates (TS — Header) includes a hardcoded Bearer token. Although this appears to be a commonly known public token for guest access, hardcoding authentication tokens in templates is a sensitive practice.
- [DATA_EXFILTRATION]: The skill demonstrates how to extract sensitive authentication data from the browser environment, specifically accessing
document.cookieandX-Csrf-Tokento facilitate authenticated API requests. - [COMMAND_EXECUTION]: The skill provides instructions for the user or agent to run shell commands such as
npm run buildandopenclifor testing and registration purposes.
Audit Metadata