kuaishou-account-works

Fail

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The Python scripts scripts/search_ks_detail.py and scripts/search_ks_work.py contain logic to read sensitive shell configuration files, including ~/.zshrc, ~/.bashrc, ~/.bash_profile, and ~/.profile, to programmatically search for and extract the REDFOX_API_KEY credential.\n- [PERSISTENCE_MECHANISMS]: The instructions in SKILL.md direct the agent to establish persistence by appending export commands to the user's shell profile files (~/.zshrc, ~/.bashrc) or by using PowerShell to modify environment variables permanently.\n- [PRIVILEGE_ESCALATION]: The skill encourages the agent to perform unauthorized or excessive modifications to user-level configuration files (shell profiles) to inject environment variables, which constitutes a persistence mechanism and potential privilege escalation.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a potential attack surface through the ingestion of external data from the redfox.hk API.\n
  • Ingestion points: The articles and detail fields from API responses processed in scripts/search_ks_work.py and scripts/search_ks_detail.py.\n
  • Boundary markers: None are explicitly defined to isolate processed content.\n
  • Capability inventory: The agent executes local Python scripts that perform network operations and file access.\n
  • Sanitization: Basic sanitization is performed on titles (escaping the | character), but the skill lacks robust validation for other remote content.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 24, 2026, 06:06 PM
Security Audit — agent-trust-hub — kuaishou-account-works