weread-skills
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill communicates exclusively with the official Tencent domain
i.weread.qq.comfor all book management and reading statistics operations. - [SAFE]: Sensitive data is handled correctly; the skill instructs the agent to retrieve the authentication token (
WEREAD_API_KEY) from environment variables rather than hardcoding credentials. - [SAFE]: No evidence of obfuscation, remote code execution, privilege escalation, or persistence mechanisms was found in the documentation or instructions.
- [SAFE]: All deep links and URL schemas (e.g.,
weread://reading) are standard for the WeRead mobile application and do not point to suspicious external sites. - [DATA_INGESTION]: The skill processes external content including book reviews and user notes from the API. However, it includes strict instructions for data formatting (e.g., Unix timestamp to YYYY-MM-DD conversion) and truncation of long reviews, which serves as a natural barrier against large-scale injection, and the skill lacks dangerous capabilities like shell execution or local file writes.
Audit Metadata