sn-search-social-cn
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from Bilibili, Douyin, and Zhihu search results without adequate boundary markers, creating a risk that malicious instructions in the content could influence the agent's behavior.
- Ingestion points: Data retrieved from
scripts/bilibili_search.py,scripts/douyin_search.py, andscripts/zhihu_search.pyincluding titles, snippets, and full text content. - Boundary markers: Absent. The data is returned as structured strings within JSON, but lacks instructions for the agent to ignore embedded commands.
- Capability inventory: The skill performs network requests and writes long-form content to temporary files.
- Sanitization: Employs
_strip_htmlto remove HTML tags, but does not sanitize the remaining text content for potential prompt injection patterns. - [COMMAND_EXECUTION]: The script
scripts/zhihu_search.pywrites long-form search result content to the local file system usingtempfile.NamedTemporaryFile(lines 133-149). This file-writing capability, when combined with the ingestion of untrusted data, provides an attack surface for indirect prompt injection. - [EXTERNAL_DOWNLOADS]: The scripts fetch data from external Chinese social media platforms (Bilibili, Douyin, and Zhihu). These are well-known services. Additionally, the
requirements.txtfile includesxhs, an unversioned third-party library used for Xiaohongshu API interactions.
Audit Metadata