searchnews

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to run shell commands using templates that incorporate raw data from external news sites, creating a potential command injection vector.
  • Evidence: SKILL.md (Section 6.3) instructs the agent to execute python text_to_image.py "{风格提示词}", where the {风格提示词} variable contains unvalidated news titles and summaries scraped from the web.
  • Evidence: The agent is required to execute a local shell script bash .opencode/skills/searchnews/scripts/ralph/ralph.sh to initialize task lists.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple external news sources and uses it in prompts for image and video generation tools without adequate isolation or sanitization.
  • Ingestion points: Technical details and news content are retrieved from external URLs (e.g., AIBase, 36Kr, IT之家, 机器之心, 量子位).
  • Boundary markers: The prompt templates for image and video generation lack delimiters or specific instructions to ignore potential commands embedded in the scraped data.
  • Sanitization: The skill does not implement filtering, escaping, or validation logic for the retrieved external data before it is interpolated into instructions.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from several third-party news websites and recommends the installation of an external utility.
  • Evidence: The skill scrapes news from multiple domains including news.aibase.com, next.ithome.com, 36kr.com, jiqizhixin.com, and qbitai.com.
  • Evidence: README.md recommends the user install the jq utility via brew install jq.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 06:24 AM
Security Audit — agent-trust-hub — searchnews