lov-anti-wechat-ai-check

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted article content to provide risk analysis and humanization rewrites, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Untrusted content is ingested from user-provided files or raw text via the scripts/analyze.py script and the agent's file-reading workflow defined in SKILL.md.
  • Boundary markers: The skill does not define or instruct the agent to use boundary markers (e.g., XML tags or delimiters) to isolate the article content from the agent's core instructions.
  • Capability inventory: The skill utilizes shell execution for the Python analysis script and has file system read/write capabilities to handle input and output humanized articles.
  • Sanitization: No sanitization, filtering, or validation is performed on the input text before it is processed by the agent.
  • [PERSISTENCE]: The SKILL.md file defines a 'Universal feedback loop' that instructs the agent to update the skill's own 'canonical' files in response to 'reusable' user feedback. This mechanism could be leveraged to persistently alter the skill's logic or instructions through a series of malicious inputs, though the process includes a mandatory pause for user confirmation before final application.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:53 AM
Security Audit — agent-trust-hub — lov-anti-wechat-ai-check