zhy-wechat-publish

Pass

Audited by Gen Agent Trust Hub on Mar 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script publish_with_cover.js executes local processes via spawnSync to run bun and node for image generation and task automation. These calls use specific file paths and fixed commands with shell: false to prevent injection.- [EXTERNAL_DOWNLOADS]: The wechat_draft.js script downloads images from URLs extracted from processed HTML content to perform automated uploads to WeChat's official media APIs.- [PROMPT_INJECTION]: An indirect prompt injection surface is present where article content is utilized to generate prompts for an automated illustrator script. Ingestion point: publish_with_cover.js. Boundary markers: None. Capability inventory: Local script execution and network access. Sanitization: Basic format stripping.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 14, 2026, 02:44 AM