llm-intelligent-public-opinion-analytics
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill provides a template for an
.envfile containing placeholders for sensitive credentials, includingMYSQL_PASSWORD,OPENAI_API_KEY,PANGU_API_KEY,SMTP_PASSWORD,WECHAT_WORK_WEBHOOK,TELEGRAM_BOT_TOKEN, and others. While these are placeholders (e.g.,your_password,your_api_key), the skill also includes a hardcoded example in theinit.pysection:CREATE USER 'hotsearch_user'@'localhost' IDENTIFIED BY 'your_password'. Instructions correctly advise users to store these in a.envfile, which is a standard safety practice. - [COMMAND_EXECUTION]: The installation instructions require executing shell commands with elevated privileges, specifically
sudo mv chromedriver /usr/local/bin/andsudo chmod +x /usr/local/bin/chromedriver. These are standard steps for installing a system-wide binary but require administrative rights. - [EXTERNAL_DOWNLOADS]: The skill instructs users to download browser drivers (ChromeDriver, EdgeDriver) from external sites and clones a repository from GitHub (
https://github.com/hmmnxkl/LLM-Based-Intelligent-Public-Opinion-Analytics-Assistant.git). These downloads are necessary for the skill's primary purpose of web scraping. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to crawl 26 hot lists across 15 platforms, including titles, descriptions, and comments. This data is then processed by an LLM for sentiment analysis and topic clustering.
- Ingestion points: Data is ingested from multiple social media platforms via the
hotsearchcrawlerspiders. - Boundary markers: The provided code snippets do not show explicit boundary markers or sanitization logic when passing crawled content to the
LLMClient.analyzemethod. - Capability inventory: The system has capabilities for database writing, sending notifications (Email, WeChat, Telegram), and generating PDF/Markdown reports.
- Sanitization: No evidence of sanitization of the crawled content (which may contain malicious prompts or HTML/Markdown injections) is visible in the instructions.
Audit Metadata