publish-zsxq-article

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local shell commands to read file content (cat) and check file metadata (ls -la) during the preparation phase.
  • [DYNAMIC_EXECUTION]: Employs evaluate_script (or browser_evaluate) to inject and execute JavaScript within the browser context. This is used to simulate complex user interactions like clipboard paste events that the editor requires for proper Markdown rendering. The implementation interpolates article content directly into a JavaScript template, which could lead to script errors or unintended code execution if the input content contains unescaped backticks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external Markdown files as its primary input, creating an attack surface where malicious content in the file could attempt to influence the agent's behavior.
  • Ingestion points: Content is read from a user-specified path on the local filesystem (SKILL.md Step 1).
  • Boundary markers: The skill instructions specify removing specific Markdown syntax (YAML frontmatter, H1 headers, horizontal rules) but do not include explicit security delimiters or "ignore instructions" prompts for the content processing.
  • Capability inventory: Access to local file reading, browser navigation to external sites, file uploads, and arbitrary JavaScript execution in the browser.
  • Sanitization: Content filtering is logic-based (e.g., stripping specific Markdown tags) rather than security-focused sanitization.
  • [EXTERNAL_DOWNLOADS]: The provided helper script scripts/copy_to_clipboard.py lists several external Python dependencies, including Pillow, pyobjc-framework-Cocoa, pywin32, and clip-util. While these are legitimate libraries for system integration, they represent external code that must be installed on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:41 AM
Security Audit — agent-trust-hub — publish-zsxq-article