wechat-search

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to retrieve and process untrusted external data from the WeChat ecosystem, creating a surface for potential indirect prompt injection attacks. \n
  • Ingestion points: Untrusted content is ingested through the search results of wechat_search_v2_search and wechat_search_v2_search_videos as described in SKILL.md. \n
  • Boundary markers: The skill instructions do not explicitly require the use of delimiters or isolation prompts when presenting the external search findings to the agent. \n
  • Capability inventory: The skill is restricted to read-only search operations through the sandbase_call_tool gateway; it does not possess capabilities for file writing, network exfiltration, or system command execution. \n
  • Sanitization: There is no evidence of filtering or sanitization procedures for the data retrieved from the WeChat platform before it is synthesized into answers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — wechat-search