story-short-scan

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
  • [DATA_EXPOSURE]: The heiyan-booklist-scraper.js script extracts the Admin-Token session cookie from the browser context when the user is logged into manage.zhangwenpindu.cn. This token is used to authenticate API requests to the platform's backend services.
  • [COMMAND_EXECUTION]: The scripts/cdp-utils.js script uses child_process.execFileSync to execute the agent-browser CLI tool, enabling browser automation and interaction with Chrome DevTools Protocol (CDP).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted metadata, including book titles and descriptions, from multiple external websites. The lack of evident sanitization for this ingested data presents a surface for indirect prompt injection when the agent processes the content for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 03:18 PM
Security Audit — agent-trust-hub — story-short-scan