skills/xyaz1313/xyskill/xy-biz-scan/Gen Agent Trust Hub

xy-biz-scan

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The script scripts/atoms-search.py makes network requests to https://api.xyskill.xyz/v1/atoms/search to retrieve business diagnosis knowledge. This domain is managed by the vendor xyaz1313.\n- [COMMAND_EXECUTION]: The agent is instructed in SKILL.md to execute the local Python script scripts/atoms-search.py to query the knowledge base.\n- [DATA_EXFILTRATION]: The search script reads configuration data from ~/.xy/config.json and transmits user-provided queries to the vendor's API. While this is functional for search, it involves processing user data on a remote server.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes business-related user input and uses it as search terms to fetch knowledge "atoms" that influence the agent's output.\n
  • Ingestion points: User input describing business problems is received in the 问诊 (Consultation) and 体检 (Physical Exam) phases in SKILL.md.\n
  • Boundary markers: None identified in the tool invocation instructions.\n
  • Capability inventory: Execution of local Python scripts (python3) and network communication (urllib.request).\n
  • Sanitization: No explicit sanitization or input validation is performed on the user's query before it is passed to the search script.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:21 AM
Security Audit — agent-trust-hub — xy-biz-scan