lov-do-they-love-me
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes WeChat chat logs (messages.jsonl), which are untrusted external data. This data is interpolated into prompts for semantic classification in scripts/semantic_label.py. 1. Ingestion points: messages.jsonl. 2. Boundary markers: The classification prompt uses a structured format (序号|上文...|本句...) to separate data. 3. Capability inventory: LLM classification via semantic_label.py, SVG generation, and geometric audit via Playwright in verify_figures.py. 4. Sanitization: The parse function in semantic_label.py uses regex to ensure the LLM output strictly matches predefined labels (work, love, life, other), preventing the LLM from executing commands or returning malicious content.
- [EXTERNAL_DOWNLOADS]: The skill requires PyYAML and playwright for its operation. scripts/validate_skill.py checks for PyYAML to validate the manifest, and scripts/verify_figures.py uses playwright for geometric verification of generated SVG cards. These are standard dependencies for the stated functionality.
Audit Metadata