skills/sky-flux/skills/1688/Gen Agent Trust Hub

1688

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local shell commands (curl) to interact with a browser automation daemon (Kimi WebBridge) running on 127.0.0.1:10086. These commands are used to navigate to URLs and execute JavaScript (evaluate) within the browser context to scrape public data.
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to google.com and 1688.com subdomains to retrieve supplier information. These are well-known, legitimate services related to the skill's primary purpose of sourcing products and contact info.
  • [PROMPT_INJECTION]: No evidence of malicious prompt injection or behavior override was found in the instructions.
  • [DATA_EXFILTRATION]: While the skill extracts contact information (phone, address, contact person), it does so from public business directory pages for the purpose of presenting them to the user. There is no evidence of sending sensitive user data to unauthorized third-party servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 05:51 PM
Security Audit — agent-trust-hub — 1688