wechat-reader

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run local shell commands like curl, tail, and a Go binary (~/go/bin/chatlog) to manage the WeChat reader service and retrieve logs.
  • [DATA_EXFILTRATION]: The skill accesses highly sensitive private communication data from WeChat group chats. While communication is restricted to 127.0.0.1, the agent is tasked with extracting and processing this personal information.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting untrusted messages from external chat participants.
  • Ingestion points: WeChat chat records fetched from the local API at http://127.0.0.1:5030/api/v1/chatlog in SKILL.md.
  • Boundary markers: Absent; no instructions or delimiters are provided to the agent to distinguish between chat data and embedded commands.
  • Capability inventory: Shell command execution, local file reading via tail, and server process management.
  • Sanitization: Absent; the agent is directed to extract tasks and decisions from raw chat content without input validation or filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — wechat-reader