wechat-article-to-markdown
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell pipelines (
cat,tr,grep) to process and filter HTML content retrieved from the web. While these are standard utilities, they represent a shell interaction surface based on external input. - [EXTERNAL_DOWNLOADS]: The skill is designed to fetch article data from the
mp.weixin.qq.comdomain using a stealthy fetch tool, which involves processing content from an external, untrusted source. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests data from external websites and processes it without semantic sanitization.
- Ingestion points: External article content is fetched through
mcp__ScraplingServer__stealthy_fetchas defined inSKILL.md. - Boundary markers: The instructions lack explicit delimiters or safety warnings to prevent the agent from following instructions embedded within the article body.
- Capability inventory: The skill has the capability to write Markdown files to the local disk and execute shell commands for data manipulation.
- Sanitization: The skill removes technical artifacts like ads and UI elements but does not filter the text content for potential adversarial instructions targeting the agent's logic.
Audit Metadata