huashu-wechat-image

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructions in SKILL.md direct the agent to read sensitive data from a local environment file at ~/.claude/.env using grep to extract GEMINI_API_KEY. While secret management is standard, direct file reads into shell environment exports increase the risk of accidental exposure.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to command injection because it interpolates untrusted user content (article titles and prompts) directly into shell command arguments in SKILL.md (e.g., --prompt "[完整prompt]"). An attacker could provide a payload designed to escape the quotes and execute arbitrary shell commands.
  • Ingestion points: User-provided article content, titles, and design descriptions in SKILL.md Step 0 and Step 3-B-3.
  • Boundary markers: None identified in the prompt templates.
  • Capability inventory: Subprocess execution via uv run and npx playwright, file writing, and network access via the Gemini API.
  • Sanitization: None visible; the skill uses direct string interpolation into shell commands.
  • [COMMAND_EXECUTION]: The skill frequently invokes shell commands, including uv run for Python script execution, npx playwright for web rendering, and grep for file processing.
  • [EXTERNAL_DOWNLOADS]: The skill references an external utility upload_image.py located at a hardcoded absolute path (/Users/alchain/Documents/写作/tools/upload_image.py) which is not part of the skill package and cannot be verified for safety. It also relies on npx playwright which dynamically downloads browser binaries.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:55 AM
Security Audit — agent-trust-hub — huashu-wechat-image