cnki-navigate-pages

Warn

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic script generation via the browser action=act kind=evaluate command. It relies on the AI to interpolate user-supplied arguments directly into JavaScript code blocks by replacing placeholders such as ACTION_HERE and SORT_HERE.\n- [PROMPT_INJECTION]: The instruction to perform direct string substitution for code creation lacks sanitization. This allows for potential injection attacks where malicious input could escape the intended string context and execute arbitrary JavaScript commands within the browser session.\n- [SAFE]: The functionality is restricted to interactions with the CNKI web interface, targeting public search result elements and standard sorting features without accessing sensitive system files or private user data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 17, 2026, 12:19 AM
Security Audit — agent-trust-hub — cnki-navigate-pages