Triage WeChat article comments, prepare safe reply drafts, and only reply, feature, delete, or change comment state with explicit user intent.
65
77%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Fix and improve this skill with Tessl
tessl review fix ./examples/plugin-packages/wechat-official/.opencode/skills/wechat-official-comments/SKILL.mdLow
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
该技能要求通过 `list-comments` 读取“已发布文章的评论”并对评论文本进行分类/草案生成,因此会直接摄取由外部用户作者(公众号读者)提交的自由文本评论内容。
bd5caef
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.