wechat-channels-research

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from WeChat Channels, including user-generated comments and video descriptions, which could contain malicious instructions for the agent.
  • Ingestion points: Data is retrieved via tools such as wechat_channels_v2_video_comments, wechat_channels_v2_video_detail, and wechat_channels_v2_search_channel_videos.
  • Capability inventory: The agent uses sandbase_call_tool to perform network operations and retrieve content from external sources.
  • Boundary markers: The instructions mandate citing sources and separating factual observations from analysis, which helps mitigate accidental obedience, though explicit delimiters for external content are missing.
  • Sanitization: There are no explicit instructions for the agent to sanitize or filter the content retrieved from the WeChat platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — wechat-channels-research