Baidu Milan Winter Olympics 2026
· v0.0.2
获取2026年米兰冬奥会数据技能,包括奖牌榜排名、现场新闻报道和赛程安排。从百度体育网页抓取实时的奖牌排行榜信息、最新新闻资讯和比赛赛程。当用户需要获取米兰冬奥会需求,需要查询冬奥会奖牌榜、了解各国奖牌数量、获取现场新闻、查看赛程安排时使用此技能。能够根据指定时间(今天、明天、yyyy-MM-dd日期格式)或指定运动项目获取赛程安排。A skill for retrieving 2026 Milan Winter Olympics data, including medal standings, live news reports, and competition schedules. Scrapes real-time medal rankings, latest news, and match schedules from Baidu Sports. Use this skill when users need to query Winter Olympics medal standings, check medal counts by country, get live news, or view competition schedules.
⚠️ Hazard Flags
📋 Capabilities
Execution
- ✅ Shell execution
- ✅ Code execution
- ❌ Install dependencies
- ❌ Persistence
- Privilege: user
Filesystem
- ❌ Read workspace
- ❌ Write workspace
- ❌ Read home
- ❌ Write home
- ❌ Read system
- ❌ Delete
Network
- Egress: any
- ❌ Ingress
Credentials
- ❌ Environment vars
- ❌ Credential files
- ❌ Browser data
- ❌ Keychain
Actions
🔒 Containment
Level: maximum
- SANDBOX_CONTAINER: Code execution capability
- LOG_ACTIONS: Audit trail for all actions
⚡ Risks
Mitigation: Remove embedded script tags and encoded payloads.
Mitigation: Provide clear, detailed description of skill functionality
Want a deeper analysis?
This report was generated by static analysis. Get an LLM-powered deep review with behavioral reasoning and attack surface mapping.
🧠 Deep Analysis — $5.00🚨 Incident Response
Kill switch: Stop the agent process
Containment: Review logs for unexpected actions
Recovery: Depends on skill capabilities
📄 Raw SSDS JSON click to expand
{
"meta": {
"document_id": "ssds:auto:baidu-milan-winter-olympics-2026:0.0.2",
"ssds_version": "0.2.0",
"scanner_version": "0.4.0+fe6fd9123d50",
"created_at": "2026-03-05T03:32:27.565Z",
"created_by": {
"agent": "safeagentskills-cli/generate-ssds"
},
"language": "en",
"notes": "Auto-generated SSDS. Manual review recommended."
},
"skill": {
"name": "Baidu Milan Winter Olympics 2026",
"version": "0.0.2",
"format": "agent_skill",
"description": "获取2026年米兰冬奥会数据技能,包括奖牌榜排名、现场新闻报道和赛程安排。从百度体育网页抓取实时的奖牌排行榜信息、最新新闻资讯和比赛赛程。当用户需要获取米兰冬奥会需求,需要查询冬奥会奖牌榜、了解各国奖牌数量、获取现场新闻、查看赛程安排时使用此技能。能够根据指定时间(今天、明天、yyyy-MM-dd日期格式)或指定运动项目获取赛程安排。A skill for retrieving 2026 Milan Winter Olympics data, including medal standings, live news reports, and competition schedules. Scrapes real-time medal rankings, latest news, and match schedules from Baidu Sports. Use this skill when users need to query Winter Olympics medal standings, check medal counts by country, get live news, or view competition schedules.",
"publisher": "unknown",
"source": {
"channel": "local"
},
"artifact": {
"sha256": "a2d5e20fa9c9ca84b67e9492c56b573ed9e4f00bdd1f7675250d6b9a84be6dc7",
"hash_method": "files_sorted"
}
},
"capabilities": {
"execution": {
"can_exec_shell": true,
"can_exec_code": true,
"privilege_level": "user",
"can_install_deps": false,
"can_persist": false
},
"filesystem": {
"reads_workspace": false,
"reads_user_home": false,
"reads_system": false,
"writes_workspace": false,
"writes_user_home": false,
"writes_system": false,
"can_delete": false
},
"network": {
"egress": "any",
"ingress": false
},
"credentials": {
"reads_env_vars": false,
"reads_credential_files": false,
"reads_browser_data": false,
"reads_keychain": false
},
"services": [],
"actions": {
"can_send_messages": false,
"can_post_public": false,
"can_purchase": false,
"can_transfer_money": false,
"can_deploy": false,
"can_delete_external": false
},
"prompt_injection_surfaces": [
"web"
],
"content_types": [
"general"
]
},
"hazards": {
"hdac": {
"H": 4,
"D": 0,
"A": 0,
"C": 1
},
"flags": [
"EXEC",
"CODE_EXEC",
"NET_EGRESS_ANY",
"PI_WEB"
],
"custom_flags": [
{
"code": "SOCIAL_ENGINEERING",
"name": "Social Engineering Risk",
"description": "SOCIAL_ENG_VAGUE_DESCRIPTION: Skill description is too vague or missing"
},
{
"code": "COMMAND_INJECTION",
"name": "Command Injection Risk",
"description": "MCP_SCRIPT_TAGS, COMMAND_INJECTION_EVAL: Script tags, VBScript, or encoded script data URIs"
}
],
"confidence": {
"level": "medium",
"basis": [
"static_analysis"
],
"notes": "Detected 2 security patterns (5 vendored rule hits). Review recommended."
},
"rationale": {
"H": "H4: Critical: Privilege escalation or malware detected",
"D": "D0: No sensitive data access",
"A": "A0: No side effects detected",
"C": "C1: General content"
}
},
"containment": {
"level": "maximum",
"required": [
{
"control": "SANDBOX_CONTAINER",
"reason": "Code execution capability"
}
],
"recommended": [
{
"control": "LOG_ACTIONS",
"reason": "Audit trail for all actions"
}
],
"uncontained_risk": "Risk level depends on manual review of actual capabilities."
},
"risks": {
"risks": [
{
"risk": "Command injection risk: MCP_SCRIPT_TAGS, COMMAND_INJECTION_EVAL",
"severity": "critical",
"mitigation": "Remove embedded script tags and encoded payloads."
},
{
"risk": "Social engineering indicators: SOCIAL_ENG_VAGUE_DESCRIPTION",
"severity": "low",
"mitigation": "Provide clear, detailed description of skill functionality"
}
],
"limitations": [
"Static analysis only - runtime behavior not verified"
]
},
"incident_response": {
"kill_switch": [
"Stop the agent process"
],
"containment": [
"Review logs for unexpected actions"
],
"recovery": [
"Depends on skill capabilities"
]
},
"evidence": [
{
"evidence_id": "EV:file-1",
"type": "file_excerpt",
"title": "scripts/milan-china-medals.js",
"file_path": "scripts/milan-china-medals.js"
},
{
"evidence_id": "EV:file-2",
"type": "file_excerpt",
"title": "scripts/milan-news.js",
"file_path": "scripts/milan-news.js"
},
{
"evidence_id": "EV:file-3",
"type": "file_excerpt",
"title": "scripts/milan-olympics.js",
"file_path": "scripts/milan-olympics.js"
},
{
"evidence_id": "EV:file-4",
"type": "file_excerpt",
"title": "scripts/milan-schedule.js",
"file_path": "scripts/milan-schedule.js"
},
{
"evidence_id": "EV:file-5",
"type": "file_excerpt",
"title": "SKILL.md",
"file_path": "SKILL.md"
},
{
"evidence_id": "EV:file-6",
"type": "file_excerpt",
"title": "_meta.json",
"file_path": "_meta.json"
},
{
"evidence_id": "EV:cisco-1",
"type": "file_excerpt",
"title": "MCP_SCRIPT_TAGS [HIGH] scripts/milan-china-medals.js:92: const scriptRegex = /<script id=\"atom-data-[^\"]*\" type=\"application\\/json\">([\\s\\",
"file_path": "scripts/milan-china-medals.js"
},
{
"evidence_id": "EV:cisco-2",
"type": "file_excerpt",
"title": "COMMAND_INJECTION_EVAL [CRITICAL] scripts/milan-news.js:138: while ((match = itemRegex.exec(html)) !== null) {",
"file_path": "scripts/milan-news.js"
},
{
"evidence_id": "EV:cisco-3",
"type": "file_excerpt",
"title": "MCP_SCRIPT_TAGS [HIGH] scripts/milan-news.js:91: const scriptRegex = /<script id=\"atom-data-[^\"]*\" type=\"application\\/json\">([\\s\\",
"file_path": "scripts/milan-news.js"
},
{
"evidence_id": "EV:cisco-4",
"type": "file_excerpt",
"title": "MCP_SCRIPT_TAGS [HIGH] scripts/milan-olympics.js:166: const jsonMatch = html.match(/<script[^>]*type=\"application\\/json\"[^>]*>([\\s\\S]*",
"file_path": "scripts/milan-olympics.js"
},
{
"evidence_id": "EV:cisco-5",
"type": "file_excerpt",
"title": "SOCIAL_ENG_VAGUE_DESCRIPTION [LOW] SKILL.md:1: ---",
"file_path": "SKILL.md"
}
]
}