wechat-article-formatter
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external Markdown files provided by the user to generate formatted HTML. Maliciously crafted Markdown files could potentially contain instructions aimed at influencing the agent's behavior during the content mapping or preview generation phases.
- Ingestion points: Markdown files are read and processed by
scripts/markdown_to_html.py,scripts/batch_convert.py, andscripts/preview_generator.py. - Boundary markers: The skill does not explicitly use delimiters or instruction-ignore warnings when presenting Markdown content to the agent for processing.
- Capability inventory: The skill utilizes
Read,Write, andBashtools, enabling it to read source files, execute conversion scripts, write HTML output, and run a local preview server. - Sanitization: There is no specific sanitization of the input Markdown to prevent embedded text from being interpreted as instructions by the agent.
- [COMMAND_EXECUTION]: The skill performs its primary functions by executing localized Python scripts (
markdown_to_html.py,batch_convert.py,preview_generator.py, andconvert-code-blocks.py) through theBashtool. This is a standard part of its operational workflow for document transformation.
Audit Metadata