docs-workflows
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external websites (Juejin, Bilibili, and various IDE homepages) to extract article metadata, video thumbnails, and IDE icons. This introduces a vulnerability surface where malicious metadata on these platforms could attempt to influence the agent's behavior.
- Ingestion points:
add_article_tutorial.md(Juejin search results and article pages),add_video_tutorial.md(Bilibili API and search results),add_aiide.md(IDE official websites). - Boundary markers: No specific delimiters or "ignore instructions" warnings are used when processing the extracted text.
- Capability inventory: The skill possesses significant capabilities including writing to the local filesystem, executing
nodescripts, runningcurlcommands, and utilizing the GitHub CLI (gh). - Sanitization: While the skill includes keyword-based relevance filters for search results, it lacks security-focused sanitization to prevent the agent from obeying instructions embedded in the extracted metadata.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute local maintenance and build scripts using Node.js. Examples include
node scripts/fix-config-hardlinks.mjsinadd_aiide.mdandnode scripts/generate-prompts.mjsinadd_skill.md. While these scripts are part of the repository, instructing the agent to execute them creates a dependency on the integrity of the project's local source code. - [EXTERNAL_DOWNLOADS]: The skill uses
curlto download remote assets, such as Bilibili thumbnails and IDE icons, into the/tmp/directory for subsequent processing and cloud storage upload.
Audit Metadata