sn-search-social-cn

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from Bilibili, Douyin, and Zhihu search results without adequate boundary markers, creating a risk that malicious instructions in the content could influence the agent's behavior.
  • Ingestion points: Data retrieved from scripts/bilibili_search.py, scripts/douyin_search.py, and scripts/zhihu_search.py including titles, snippets, and full text content.
  • Boundary markers: Absent. The data is returned as structured strings within JSON, but lacks instructions for the agent to ignore embedded commands.
  • Capability inventory: The skill performs network requests and writes long-form content to temporary files.
  • Sanitization: Employs _strip_html to remove HTML tags, but does not sanitize the remaining text content for potential prompt injection patterns.
  • [COMMAND_EXECUTION]: The script scripts/zhihu_search.py writes long-form search result content to the local file system using tempfile.NamedTemporaryFile (lines 133-149). This file-writing capability, when combined with the ingestion of untrusted data, provides an attack surface for indirect prompt injection.
  • [EXTERNAL_DOWNLOADS]: The scripts fetch data from external Chinese social media platforms (Bilibili, Douyin, and Zhihu). These are well-known services. Additionally, the requirements.txt file includes xhs, an unversioned third-party library used for Xiaohongshu API interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:52 AM
Security Audit — agent-trust-hub — sn-search-social-cn