wechat-reader
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run local shell commands like
curl,tail, and a Go binary (~/go/bin/chatlog) to manage the WeChat reader service and retrieve logs. - [DATA_EXFILTRATION]: The skill accesses highly sensitive private communication data from WeChat group chats. While communication is restricted to
127.0.0.1, the agent is tasked with extracting and processing this personal information. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting untrusted messages from external chat participants.
- Ingestion points: WeChat chat records fetched from the local API at
http://127.0.0.1:5030/api/v1/chatloginSKILL.md. - Boundary markers: Absent; no instructions or delimiters are provided to the agent to distinguish between chat data and embedded commands.
- Capability inventory: Shell command execution, local file reading via
tail, and server process management. - Sanitization: Absent; the agent is directed to extract tasks and decisions from raw chat content without input validation or filtering.
Audit Metadata