wechat-tech-writer

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow where it fetches external information using WebSearch and WebFetch tools (as defined in SKILL.md, Steps 2 and 3) and then instructs the agent to analyze and rewrite this content. This design creates a vulnerability to indirect prompt injection if the fetched web pages contain malicious instructions intended to hijack the agent's behavior. \n- Ingestion points: External data is ingested through search and fetch operations in SKILL.md. \n- Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded commands within the fetched content. \n- Capability inventory: The agent has access to Bash, Write, Edit, Read, WebSearch, and WebFetch. \n- Sanitization: Absent; the instructions only require the agent to use its own language for rewriting, which does not provide security sanitization. \n- [COMMAND_EXECUTION]: The skill requires the agent to execute local Python scripts (e.g., scripts/generate_image.py, scripts/generate_cover_optimized.py) using the Bash tool. These scripts facilitate image generation by communicating with external APIs (Google Gemini and OpenAI DALL-E). While these scripts are functional components of the skill, the execution of local code that takes user-influenced strings (such as article titles and subtitles) as arguments is a notable capability that should be monitored.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 02:56 PM