微信公众号已发布作品数据抓取,写入 published-track的 pub_wx_mp 表。wx_mp session 登录。
53
60%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Fix and improve this skill with Tessl
tessl review fix ./crews/main/skills/wx-mp-engagement/SKILL.mdLow
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
In scripts/fetch_engagement.py the workflow logs into mp.weixin.qq.com and then fetches the creator “发表记录” list page using the logged-in session token and immediately ingests free text from that page via `document.body.innerText` (camoufox_eval with `_LIST_PARSE_JS`) to extract titles/metrics.
fdc03d6
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.