cnki-search

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Employs Chrome DevTools protocols to programmatically navigate and interact with the kns.cnki.net web interface.
  • [DYNAMIC_EXECUTION]: Dynamically constructs JavaScript code by interpolating search keywords into a template string, which is then executed within the browser's context via developer tools. This pattern poses a minor code injection risk within the web session if inputs are not properly sanitized.
  • [INDIRECT_PROMPT_INJECTION]: The skill extracts and processes untrusted content (titles, author names, and publication details) from external web pages, presenting an attack surface where malicious data in search results could attempt to influence subsequent agent actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:50 PM
Security Audit — agent-trust-hub — cnki-search