smart-search

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs automated navigation to and downloads content from numerous external platforms to retrieve search results. Affected domains include well-known services like bing.com, baidu.com, zhihu.com, xiaohongshu.com, douyin.com, bilibili.com, weibo.com, youtube.com, x.com, reddit.com, github.com, linkedin.com, reuters.com, xueqiu.com, and arxiv.org. These downloads are part of the skill's primary function but involve interacting with a large surface area of external content.- [COMMAND_EXECUTION]: The skill utilizes the camoufox-cli tool to execute shell commands for browser automation. The skill documentation describes the use of commands such as open, snapshot, click, type, and scroll to interact with web pages. A specific mention of a custom upload command in sites/wechat-channels.md indicates the tool's capability to interact with the local file system to upload content to remote platforms.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the ingestion and processing of untrusted web content. The following evidence chain applies: 1. Ingestion points: Web content retrieved via camoufox-cli snapshot across all site-specific search scripts (e.g., sites/douyin.md, sites/xiaohongshu.md). 2. Boundary markers: The skill instructions do not provide specific delimiters or ignore-instructions to isolate the retrieved web content from the agent's control logic. 3. Capability inventory: The skill has browser navigation, form interaction, and file upload capabilities (as documented in sites/wechat-channels.md). 4. Sanitization: There is no evidence of sanitization or filtering logic applied to the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 06:38 AM
Security Audit — agent-trust-hub — smart-search