ai-model-wechat

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an ingestion surface for untrusted user messages to be passed to AI models and provides the agent with capabilities to modify environment configurations (e.g., enabling models via UpdateAIModel) based on user requests. This surface is inherent to the skill's primary purpose.
  • Ingestion points: messages array in generateText and streamText function calls within SKILL.md.
  • Boundary markers: No explicit delimiters or instruction-ignore warnings are included in the code templates.
  • Capability inventory: The skill leverages callCloudApi for the tcb service to perform administrative actions such as UpdateAIModel, CreateAIModel, and DescribeAIModels.
  • Sanitization: The skill focuses on functional logic and does not describe specific validation or escaping for user-provided strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 02:51 AM
Security Audit — agent-trust-hub — ai-model-wechat