wechat-article-to-markdown

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell pipelines (cat, tr, grep) to process and filter HTML content retrieved from the web. While these are standard utilities, they represent a shell interaction surface based on external input.
  • [EXTERNAL_DOWNLOADS]: The skill is designed to fetch article data from the mp.weixin.qq.com domain using a stealthy fetch tool, which involves processing content from an external, untrusted source.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests data from external websites and processes it without semantic sanitization.
  • Ingestion points: External article content is fetched through mcp__ScraplingServer__stealthy_fetch as defined in SKILL.md.
  • Boundary markers: The instructions lack explicit delimiters or safety warnings to prevent the agent from following instructions embedded within the article body.
  • Capability inventory: The skill has the capability to write Markdown files to the local disk and execute shell commands for data manipulation.
  • Sanitization: The skill removes technical artifacts like ads and UI elements but does not filter the text content for potential adversarial instructions targeting the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — wechat-article-to-markdown