searchnews
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to run shell commands using templates that incorporate raw data from external news sites, creating a potential command injection vector.
- Evidence: SKILL.md (Section 6.3) instructs the agent to execute
python text_to_image.py "{风格提示词}", where the{风格提示词}variable contains unvalidated news titles and summaries scraped from the web. - Evidence: The agent is required to execute a local shell script
bash .opencode/skills/searchnews/scripts/ralph/ralph.shto initialize task lists. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple external news sources and uses it in prompts for image and video generation tools without adequate isolation or sanitization.
- Ingestion points: Technical details and news content are retrieved from external URLs (e.g., AIBase, 36Kr, IT之家, 机器之心, 量子位).
- Boundary markers: The prompt templates for image and video generation lack delimiters or specific instructions to ignore potential commands embedded in the scraped data.
- Sanitization: The skill does not implement filtering, escaping, or validation logic for the retrieved external data before it is interpolated into instructions.
- [EXTERNAL_DOWNLOADS]: The skill fetches content from several third-party news websites and recommends the installation of an external utility.
- Evidence: The skill scrapes news from multiple domains including
news.aibase.com,next.ithome.com,36kr.com,jiqizhixin.com, andqbitai.com. - Evidence: README.md recommends the user install the
jqutility viabrew install jq.
Audit Metadata