baoyu-wechat-summary

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes the wx command-line utility to fetch chat history and manage sessions. The skill requires dangerouslyDisableSandbox: true to interact with the external binary and its configuration.
  • [DATA_EXFILTRATION]: Accesses sensitive local directories including ~/.wx-cli/ and WeChat's internal data container on macOS (~/Library/Containers/com.tencent.xinWeChat/) to retrieve message logs. While no external exfiltration to unknown domains was detected, the access to private chat data is a sensitive operation central to the skill's purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted chat messages that could contain malicious instructions designed to influence the agent.
  • Ingestion points: Raw chat messages are retrieved via wx history and stored in a temporary JSON file ($TMPDIR/wx-messages.json) for processing.
  • Boundary markers: The skill includes a dedicated reference file (references/group-memory.md) with a section on 'Injection defense' (防注入) that warns against adopting instructions found in chat messages.
  • Capability inventory: The agent has capabilities to execute shell commands (wx) and write to various local files including history.json, Markdown digests, and user profile files in the user's project or configuration directories.
  • Sanitization: The skill implements a 'conservative writing' policy for group memory, specifically checking for and discarding behavioral instructions disguised as factual corrections as documented in Step 8.6.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:37 AM
Security Audit — agent-trust-hub — baoyu-wechat-summary