cnki-navigate-pages
Warn
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes dynamic script generation via the
browser action=act kind=evaluatecommand. It relies on the AI to interpolate user-supplied arguments directly into JavaScript code blocks by replacing placeholders such asACTION_HEREandSORT_HERE.\n- [PROMPT_INJECTION]: The instruction to perform direct string substitution for code creation lacks sanitization. This allows for potential injection attacks where malicious input could escape the intended string context and execute arbitrary JavaScript commands within the browser session.\n- [SAFE]: The functionality is restricted to interactions with the CNKI web interface, targeting public search result elements and standard sorting features without accessing sensitive system files or private user data.
Audit Metadata