huashu-weread-advisor
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill employs shell commands for automated update checks within
SKILL.md, specifically usinggit -C <path> rev-parse HEADandgit -C <path> ls-remote origin HEAD. Additionally, Python templates provided inshared/shelf-cross-notes.mdutilizesubprocess.runto executecurlfor API interactions. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted user-generated content (notes and highlights) fetched from the WeRead API.
- Ingestion points: Data enters the agent context through API responses processed in
workflows/alchemy.mdandshared/shelf-cross-notes.md. - Boundary markers: The instructions lack explicit delimiters or instructions to ignore embedded commands within the fetched reading notes.
- Capability inventory: The skill environment allows shell command execution and network operations via
curlandgit. - Sanitization: There is no evidence of filtering or escaping logic applied to the content of notes before they are processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill fetches data and checks for updates from well-known services, including the official WeRead API (
i.weread.qq.com) and GitHub repositories. These operations are essential for the skill's stated functionality and target trusted infrastructure. - [DATA_EXFILTRATION]: The skill transmits the user's
WEREAD_API_KEYand reading data tohttps://i.weread.qq.com/api/agent/gateway. This is a neutral finding as it represents the core intended functionality of the service using a user-provided credential.
Audit Metadata