llm-public-opinion-analytics-assistant
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires cloning code from an external GitHub repository (github.com/hmmnxkl/LLM-Based-Intelligent-Public-Opinion-Analytics-Assistant.git) that is not managed by the skill author.
- [PRIVILEGE_ESCALATION]: Installation instructions require the user to execute commands with elevated privileges (sudo) to move binaries into system-protected directories (/usr/local/bin/) and change file permissions (chmod +x) on external executables.
- [COMMAND_EXECUTION]: The skill instructions involve executing multiple shell commands for environment setup, process management, and system-level driver verification.
- [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it ingests large amounts of untrusted data from 15 platforms (Weibo, Bilibili, etc.) and processes it using an LLM. Ingestion points: Social media content via platform-specific Scrapy spiders in SKILL.md. Boundary markers: No explicit delimiters or safety instructions are defined to separate crawled content from the agent's core instructions. Capability inventory: The agent has capabilities for network operations (SMTP, WeChat/Telegram APIs), database writes (MySQL), and execution of crawler processes across the documented scripts. Sanitization: No sanitization or filtering of external content is documented prior to LLM processing.
Recommendations
- AI detected serious security threats
Audit Metadata