skills/khanhhuyenngo985-sys/character-scene-design-skills/media-monitor-automation/Gen Agent Trust Hub
media-monitor-automation
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [PERSISTENCE_MECHANISMS]: The skill uses Cron jobs to automate daily media monitoring (8:00 AM) and weekly health checks (Sunday 2:00 AM) via
setup-cron.shandscanner.py. - [COMMAND_EXECUTION]: Instructions include executing local shell commands and Python scripts (
media-monitor.py,setup-cron.sh) to perform monitoring, health checks, and configuration updates. - [EXTERNAL_DOWNLOADS]: The skill uses
curlto fetch content from various external RSS feed URLs for source validation and continuous data ingestion. It also suggests checkingrsshub.app, a well-known RSS generation service. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Data is ingested from external RSS feeds defined in the
RSS_SOURCESconfiguration withinmedia-monitor.py. - Boundary markers: No specific delimiters or safety instructions are defined to separate untrusted external content from the agent's instructions.
- Capability inventory: The skill has the capability to write ingested data to local directories (
~/Documents/白梦客知识库/) and execute Python-based processing scripts. - Sanitization: The skill mentions using "loose parsing" for RSS formatting, which may fail to filter malicious instructions embedded in feed metadata or body content.
Audit Metadata