lov-anti-wechat-ai-check
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted article content to provide risk analysis and humanization rewrites, creating a surface for indirect prompt injection attacks.
- Ingestion points: Untrusted content is ingested from user-provided files or raw text via the
scripts/analyze.pyscript and the agent's file-reading workflow defined inSKILL.md. - Boundary markers: The skill does not define or instruct the agent to use boundary markers (e.g., XML tags or delimiters) to isolate the article content from the agent's core instructions.
- Capability inventory: The skill utilizes shell execution for the Python analysis script and has file system read/write capabilities to handle input and output humanized articles.
- Sanitization: No sanitization, filtering, or validation is performed on the input text before it is processed by the agent.
- [PERSISTENCE]: The
SKILL.mdfile defines a 'Universal feedback loop' that instructs the agent to update the skill's own 'canonical' files in response to 'reusable' user feedback. This mechanism could be leveraged to persistently alter the skill's logic or instructions through a series of malicious inputs, though the process includes a mandatory pause for user confirmation before final application.
Audit Metadata