story-short-scan
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
- [DATA_EXPOSURE]: The
heiyan-booklist-scraper.jsscript extracts theAdmin-Tokensession cookie from the browser context when the user is logged intomanage.zhangwenpindu.cn. This token is used to authenticate API requests to the platform's backend services. - [COMMAND_EXECUTION]: The
scripts/cdp-utils.jsscript useschild_process.execFileSyncto execute theagent-browserCLI tool, enabling browser automation and interaction with Chrome DevTools Protocol (CDP). - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted metadata, including book titles and descriptions, from multiple external websites. The lack of evident sanitization for this ingested data presents a surface for indirect prompt injection when the agent processes the content for analysis.
Audit Metadata