wechat-search
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to retrieve and process untrusted external data from the WeChat ecosystem, creating a surface for potential indirect prompt injection attacks. \n
- Ingestion points: Untrusted content is ingested through the search results of
wechat_search_v2_searchandwechat_search_v2_search_videosas described inSKILL.md. \n - Boundary markers: The skill instructions do not explicitly require the use of delimiters or isolation prompts when presenting the external search findings to the agent. \n
- Capability inventory: The skill is restricted to read-only search operations through the
sandbase_call_toolgateway; it does not possess capabilities for file writing, network exfiltration, or system command execution. \n - Sanitization: There is no evidence of filtering or sanitization procedures for the data retrieved from the WeChat platform before it is synthesized into answers.
Audit Metadata