lov-read-wechat-article
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/ocr_images.pyusessubprocess.runto executeswiftfor macOS Vision OCR andtesseractfor fallback OCR. The commands are constructed using lists (avoiding shell injection) and reference a local scriptvision_ocr.swiftprovided within the skill's own directory. This is standard behavior for facilitating the stated OCR functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content from WeChat article URLs and generates Markdown.
- Ingestion points: WeChat article HTML content fetched via
urllibinscripts/read_wechat_article.py. - Boundary markers: The skill instructs the agent to use explicit markers like '> 本文件由公众号原文整理为 Markdown' and '## 来源与说明'.
- Capability inventory: The skill can write files (
.md,.json,.html), download images, and execute local OCR tools via subprocess. - Sanitization: Uses
HTMLParserfor content extraction and includes manual 'visual verification' steps for the agent to ensure OCR accuracy and fact-checking, which helps mitigate potential injection content from the source article. - [SAFE]: The
scripts/profile_store.pyutility handles local configuration storage for user preferences. It includes a specific security check to block sensitive field names (e.g., 'token', 'secret', 'api_key') from being persisted in the profile, following best practices for credential safety.
Audit Metadata