baoyu-wechat-summary
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes the
wxcommand-line utility to fetch chat history and manage sessions. The skill requiresdangerouslyDisableSandbox: trueto interact with the external binary and its configuration. - [DATA_EXFILTRATION]: Accesses sensitive local directories including
~/.wx-cli/and WeChat's internal data container on macOS (~/Library/Containers/com.tencent.xinWeChat/) to retrieve message logs. While no external exfiltration to unknown domains was detected, the access to private chat data is a sensitive operation central to the skill's purpose. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted chat messages that could contain malicious instructions designed to influence the agent.
- Ingestion points: Raw chat messages are retrieved via
wx historyand stored in a temporary JSON file ($TMPDIR/wx-messages.json) for processing. - Boundary markers: The skill includes a dedicated reference file (
references/group-memory.md) with a section on 'Injection defense' (防注入) that warns against adopting instructions found in chat messages. - Capability inventory: The agent has capabilities to execute shell commands (
wx) and write to various local files includinghistory.json, Markdown digests, and user profile files in the user's project or configuration directories. - Sanitization: The skill implements a 'conservative writing' policy for group memory, specifically checking for and discarding behavioral instructions disguised as factual corrections as documented in Step 8.6.
Audit Metadata