alicloud-ai-content-aicontent-test

Pass

Audited by Gen Agent Trust Hub on Apr 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes a local Python script (tests/common/compile_skill_scripts.py) to validate skill compilation as part of the smoke test process.- [COMMAND_EXECUTION]: Dynamically identifies and executes Alibaba Cloud API calls (e.g., Describe*, List*) based on content parsed from an external SKILL.md file at runtime.- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it ingests data from skills/ai/content/alicloud-ai-content-aicontent/SKILL.md and uses that content to determine the agent's next capability execution (API calls). Evidence chain: 1. Ingestion point: skills/ai/content/alicloud-ai-content-aicontent/SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: python3 command execution and Cloud API execution. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 4, 2026, 02:31 PM