huashu-wechat-image
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructions in
SKILL.mddirect the agent to read sensitive data from a local environment file at~/.claude/.envusinggrepto extractGEMINI_API_KEY. While secret management is standard, direct file reads into shell environment exports increase the risk of accidental exposure. - [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to command injection because it interpolates untrusted user content (article titles and prompts) directly into shell command arguments in
SKILL.md(e.g.,--prompt "[完整prompt]"). An attacker could provide a payload designed to escape the quotes and execute arbitrary shell commands. - Ingestion points: User-provided article content, titles, and design descriptions in
SKILL.mdStep 0 and Step 3-B-3. - Boundary markers: None identified in the prompt templates.
- Capability inventory: Subprocess execution via
uv runandnpx playwright, file writing, and network access via the Gemini API. - Sanitization: None visible; the skill uses direct string interpolation into shell commands.
- [COMMAND_EXECUTION]: The skill frequently invokes shell commands, including
uv runfor Python script execution,npx playwrightfor web rendering, andgrepfor file processing. - [EXTERNAL_DOWNLOADS]: The skill references an external utility
upload_image.pylocated at a hardcoded absolute path (/Users/alchain/Documents/写作/tools/upload_image.py) which is not part of the skill package and cannot be verified for safety. It also relies onnpx playwrightwhich dynamically downloads browser binaries.
Audit Metadata