docs-workflows

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites (Juejin, Bilibili, and various IDE homepages) to extract article metadata, video thumbnails, and IDE icons. This introduces a vulnerability surface where malicious metadata on these platforms could attempt to influence the agent's behavior.
  • Ingestion points: add_article_tutorial.md (Juejin search results and article pages), add_video_tutorial.md (Bilibili API and search results), add_aiide.md (IDE official websites).
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are used when processing the extracted text.
  • Capability inventory: The skill possesses significant capabilities including writing to the local filesystem, executing node scripts, running curl commands, and utilizing the GitHub CLI (gh).
  • Sanitization: While the skill includes keyword-based relevance filters for search results, it lacks security-focused sanitization to prevent the agent from obeying instructions embedded in the extracted metadata.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute local maintenance and build scripts using Node.js. Examples include node scripts/fix-config-hardlinks.mjs in add_aiide.md and node scripts/generate-prompts.mjs in add_skill.md. While these scripts are part of the repository, instructing the agent to execute them creates a dependency on the integrity of the project's local source code.
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to download remote assets, such as Bilibili thumbnails and IDE icons, into the /tmp/ directory for subsequent processing and cloud storage upload.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:31 AM
Security Audit — agent-trust-hub — docs-workflows