1688
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands (
curl) to interact with a browser automation daemon (Kimi WebBridge) running on127.0.0.1:10086. These commands are used to navigate to URLs and execute JavaScript (evaluate) within the browser context to scrape public data. - [EXTERNAL_DOWNLOADS]: The skill performs network requests to
google.comand1688.comsubdomains to retrieve supplier information. These are well-known, legitimate services related to the skill's primary purpose of sourcing products and contact info. - [PROMPT_INJECTION]: No evidence of malicious prompt injection or behavior override was found in the instructions.
- [DATA_EXFILTRATION]: While the skill extracts contact information (phone, address, contact person), it does so from public business directory pages for the purpose of presenting them to the user. There is no evidence of sending sensitive user data to unauthorized third-party servers.
Audit Metadata