weread
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill leverages the
weread-omniCLI for all operations, ensuring structured interaction with WeRead data through JSON-formatted shell commands. - [DATA_EXFILTRATION]: Security instructions explicitly prohibit the display of raw authentication tokens or credentials, and limit article retrieval to a validated WeChat domain with no authentication headers sent to that host.
- [INDIRECT_PROMPT_INJECTION]: The skill mitigates risks associated with processing external articles and book text by requiring explicit user confirmation and specific command-line flags for any destructive actions like deletions.
Audit Metadata