Design safe WeChat follower-message automation and send customer-service text only when the user provides an explicit target and confirmation.
57
64%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Fix and improve this skill with Tessl
tessl review fix ./examples/plugin-packages/wechat-official/.opencode/skills/wechat-official-messages/SKILL.mdLow
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
该技能在运行时“实时收取微信消息、关键词自动回复”,因此需要读取外部用户/公众号侧的自由文本消息来决定回复内容,存在被作为注入载体的间接提示风险。
bd5caef
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.