auto-weixin-video
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided strings for video titles and tags, which are then interpolated into browser automation scripts.
- Ingestion points: Command-line arguments processed in
scripts/publish.py. - Boundary markers: Absent; user input is directly typed into the browser via Playwright.
- Capability inventory: The skill uses browser automation (Playwright) which has network access and local file system access (reading videos).
- Sanitization: The
format_short_titlefunction inscripts/publish.pyperforms character filtering, providing some protection for the short title field, though the main title and tags are used as-is. - [COMMAND_EXECUTION]: The skill instructions involve running multiple Python scripts (
get_cookie.py,check_cookie.py, andpublish.py) to manage the video upload lifecycle. - [EXTERNAL_DOWNLOADS]: The installation process requires downloading the Chromium browser via
playwright install chromium. This is a documented and standard procedure for the Playwright automation framework. - [CREDENTIALS_UNSAFE]: The skill stores and retrieves session authentication data in a local JSON file (
cookies/weixin_video.json). This management of sensitive session tokens is a necessary component of the skill's automation functionality, but it involves handling sensitive credential data on the local file system.
Audit Metadata