weitoutiao-creator
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data during its 'Material Source Selection' phase (Step 2). It ingests 'hot topics' via web search and user-provided 'viral copy links' to perform analysis and structural disassembly.
- Ingestion points: SKILL.md (Step 2, Path 1 and Path 2) where the agent fetches and analyzes external text/URLs.
- Boundary markers: Absent. The instructions do not define clear delimiters or include warnings to ignore instructions embedded in the external content.
- Capability inventory: The agent uses tools for online searching and content analysis.
- Sanitization: Absent. There is no evidence of filtering or escaping of the ingested external content.
- [PROMPT_INJECTION]: The skill contains explicit instructions to bypass content moderation filters using obfuscation techniques.
- Evidence: The 'Sensitive Word Avoidance Guide' (敏感词规避指南) in SKILL.md instructs the agent to use pinyin or emojis to replace politically sensitive words and to use non-committal language to bypass financial and medical guidelines. While targeted at the output platform (Toutiao), these instructions train the model in bypass and evasion techniques.
- [COMMAND_EXECUTION]: The skill implies the use of network-connected tools to fulfill its purpose.
- Evidence: SKILL.md (Step 2, Path 1) mentions '联网查询相关信息' (querying relevant information online), which indicates the agent will execute network-based search tools to fetch external data.
Audit Metadata