skills/imraywang/wewrite/wewrite/Gen Agent Trust Hub

wewrite

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches external information to assist in article writing, creating a potential vector for malicious content to influence the agent.
  • Ingestion points: WebSearch and WebFetch tools are used in the content gathering phase (SKILL.md, Step 3-4).
  • Boundary markers: There are no specific delimiters or instructions provided to the agent to isolate external web content from the system instructions.
  • Capability inventory: The skill utilizes the Bash tool to execute system commands and has Write and Edit permissions for file system modification.
  • Sanitization: The instructions lack specific security-focused sanitization or validation of the fetched external data.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to interact with the wewrite CLI for workflow management, task state updates, and publishing permissions. While these operations are functional, they involve passing parameters that can be influenced by external inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:32 AM
Security Audit — agent-trust-hub — wewrite