weitoutiao-creator

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data during its 'Material Source Selection' phase (Step 2). It ingests 'hot topics' via web search and user-provided 'viral copy links' to perform analysis and structural disassembly.
  • Ingestion points: SKILL.md (Step 2, Path 1 and Path 2) where the agent fetches and analyzes external text/URLs.
  • Boundary markers: Absent. The instructions do not define clear delimiters or include warnings to ignore instructions embedded in the external content.
  • Capability inventory: The agent uses tools for online searching and content analysis.
  • Sanitization: Absent. There is no evidence of filtering or escaping of the ingested external content.
  • [PROMPT_INJECTION]: The skill contains explicit instructions to bypass content moderation filters using obfuscation techniques.
  • Evidence: The 'Sensitive Word Avoidance Guide' (敏感词规避指南) in SKILL.md instructs the agent to use pinyin or emojis to replace politically sensitive words and to use non-committal language to bypass financial and medical guidelines. While targeted at the output platform (Toutiao), these instructions train the model in bypass and evasion techniques.
  • [COMMAND_EXECUTION]: The skill implies the use of network-connected tools to fulfill its purpose.
  • Evidence: SKILL.md (Step 2, Path 1) mentions '联网查询相关信息' (querying relevant information online), which indicates the agent will execute network-based search tools to fetch external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 05:57 PM
Security Audit — agent-trust-hub — weitoutiao-creator