wechat-channels-research
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from WeChat Channels, including user-generated comments and video descriptions, which could contain malicious instructions for the agent.
- Ingestion points: Data is retrieved via tools such as
wechat_channels_v2_video_comments,wechat_channels_v2_video_detail, andwechat_channels_v2_search_channel_videos. - Capability inventory: The agent uses
sandbase_call_toolto perform network operations and retrieve content from external sources. - Boundary markers: The instructions mandate citing sources and separating factual observations from analysis, which helps mitigate accidental obedience, though explicit delimiters for external content are missing.
- Sanitization: There are no explicit instructions for the agent to sanitize or filter the content retrieved from the WeChat platform.
Audit Metadata