wechat-tech-writer
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow where it fetches external information using
WebSearchandWebFetchtools (as defined inSKILL.md, Steps 2 and 3) and then instructs the agent to analyze and rewrite this content. This design creates a vulnerability to indirect prompt injection if the fetched web pages contain malicious instructions intended to hijack the agent's behavior. \n- Ingestion points: External data is ingested through search and fetch operations inSKILL.md. \n- Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded commands within the fetched content. \n- Capability inventory: The agent has access toBash,Write,Edit,Read,WebSearch, andWebFetch. \n- Sanitization: Absent; the instructions only require the agent to use its own language for rewriting, which does not provide security sanitization. \n- [COMMAND_EXECUTION]: The skill requires the agent to execute local Python scripts (e.g.,scripts/generate_image.py,scripts/generate_cover_optimized.py) using theBashtool. These scripts facilitate image generation by communicating with external APIs (Google Gemini and OpenAI DALL-E). While these scripts are functional components of the skill, the execution of local code that takes user-influenced strings (such as article titles and subtitles) as arguments is a notable capability that should be monitored.
Audit Metadata