alicloud-ai-content-aicontent-test
Pass
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes a local Python script (
tests/common/compile_skill_scripts.py) to validate skill compilation as part of the smoke test process.- [COMMAND_EXECUTION]: Dynamically identifies and executes Alibaba Cloud API calls (e.g.,Describe*,List*) based on content parsed from an externalSKILL.mdfile at runtime.- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it ingests data fromskills/ai/content/alicloud-ai-content-aicontent/SKILL.mdand uses that content to determine the agent's next capability execution (API calls). Evidence chain: 1. Ingestion point:skills/ai/content/alicloud-ai-content-aicontent/SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory:python3command execution and Cloud API execution. 4. Sanitization: Absent.
Audit Metadata