lov-read-wechat-article

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/ocr_images.py uses subprocess.run to execute swift for macOS Vision OCR and tesseract for fallback OCR. The commands are constructed using lists (avoiding shell injection) and reference a local script vision_ocr.swift provided within the skill's own directory. This is standard behavior for facilitating the stated OCR functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content from WeChat article URLs and generates Markdown.
  • Ingestion points: WeChat article HTML content fetched via urllib in scripts/read_wechat_article.py.
  • Boundary markers: The skill instructs the agent to use explicit markers like '> 本文件由公众号原文整理为 Markdown' and '## 来源与说明'.
  • Capability inventory: The skill can write files (.md, .json, .html), download images, and execute local OCR tools via subprocess.
  • Sanitization: Uses HTMLParser for content extraction and includes manual 'visual verification' steps for the agent to ensure OCR accuracy and fact-checking, which helps mitigate potential injection content from the source article.
  • [SAFE]: The scripts/profile_store.py utility handles local configuration storage for user preferences. It includes a specific security check to block sensitive field names (e.g., 'token', 'secret', 'api_key') from being persisted in the profile, following best practices for credential safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 04:29 PM
Security Audit — agent-trust-hub — lov-read-wechat-article