huashu-weread-advisor

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs shell commands for automated update checks within SKILL.md, specifically using git -C <path> rev-parse HEAD and git -C <path> ls-remote origin HEAD. Additionally, Python templates provided in shared/shelf-cross-notes.md utilize subprocess.run to execute curl for API interactions.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted user-generated content (notes and highlights) fetched from the WeRead API.
  • Ingestion points: Data enters the agent context through API responses processed in workflows/alchemy.md and shared/shelf-cross-notes.md.
  • Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands within the fetched reading notes.
  • Capability inventory: The skill environment allows shell command execution and network operations via curl and git.
  • Sanitization: There is no evidence of filtering or escaping logic applied to the content of notes before they are processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data and checks for updates from well-known services, including the official WeRead API (i.weread.qq.com) and GitHub repositories. These operations are essential for the skill's stated functionality and target trusted infrastructure.
  • [DATA_EXFILTRATION]: The skill transmits the user's WEREAD_API_KEY and reading data to https://i.weread.qq.com/api/agent/gateway. This is a neutral finding as it represents the core intended functionality of the service using a user-provided credential.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:52 AM
Security Audit — agent-trust-hub — huashu-weread-advisor