CtrlK
BlogDocsLog inGet started
Tessl Logo

wewrite-topic

WeWrite 选题模块:抓取全网热点 + 垂类高频需求 + 历史表现分析 + 搜索需求,为公众号 生成 10 个评分排序的选题(含高频角度与常青选题)。 触发关键词:公众号选题、找几个选题、今天写什么、热点选题、热搜选题、爆款选题、选题建议。 需要公众号/微信上下文;不应被抖音/短视频/网站的选题需求触发。

Invalid
This skill can't be scored yet
Validation errors are blocking scoring. Review and fix them to unlock Quality, Impact and Security scores. See what needs fixing →
SKILL.md
Quality
Evals
Security

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

At runtime the skill can ingest outsider-authored free text via “热点抓取/ WebSearch” and “搜狗结果” in steps 2.1 and 2.1b, which then feed into LLM-based topic generation using the prompt rules in `references/topic-selection.md` (despite some being “degraded”/skipped on errors, when available they are parsed into JSON lists with title/description/urls/summaries/attributes).

Report incorrect finding
Repository
imraywang/wewrite
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.