Back to skill

Security audit

Wechat Publisher

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real WeChat publishing skill, but it handles account secrets insecurely and can modify the user's system by automatically installing a global package.

Review carefully before installing. Prefer installing a reviewed, pinned wenyan-cli version yourself, do not store AppSecret in TOOLS.md or shell startup files, use a secret manager or tightly scoped environment injection, and review all article text and images before publishing because they will be sent to WeChat services. Rotate any WeChat AppSecret already stored in shared docs, repositories, backups, or shell profiles.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/publish.sh:19
Finding

Automatic Global Installation of an Unpinned Third-Party Dependency

Content
View full analysis
/dev/null; then echo -e "${RED}❌ wenyan-cli 未安装!${NC}" echo -e "${YELLOW}正在安装 wenyan-cli...${NC}" npm install -g @wenyan-md/cli if [ $? -eq 0 ]; then echo -e "${GREEN}✅ wenyan-cli 安装成功!${NC}" else echo -e "${RED}❌ 安装失败!请手动运行: npm install -g @wenyan-md/cli${NC}" exit 1 fi fi } ``` ### Technical Analysis The publishing script automatically runs `npm install -g @wenyan-md/cli` when it cannot find a `wenyan` executable. The dependency is referenced without an exact version, lockfile, or integrity constraint. Consequently, the code installed depends on the package and dependency versions available from the configured npm registry at execution time rather than the versions reviewed with this Skill. npm installation can execute package lifecycle scripts. A compromised package release, compromised transitive dependency, registry takeover, or maliciously configured npm registry could therefore result in arbitrary local code execution. The global installation flag also modifies the user's global Node.js environment and may require elevated privileges on some systems. The installation occurs as an implicit side effect of invoking the publishing workflow. The script does not request confirmation, display the resolved version, validate package integrity, or constrain lifecycle scripts. ### Attack Path 1. A user invokes `scripts/publish.sh` on a system where `wenyan` is not installed or is not available through `PATH`. 2. The script automatically contacts the npm registry configured on the system. 3. npm resolves the latest available release of `@wenyan-md/cli` and its transitive dependencie ...[truncated 1037 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/publish.sh:33
Finding

WeChat AppSecret Stored and Loaded from a Shared Plaintext Workspace File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill’s stated purpose is Markdown-to-WeChat publishing, but the documentation also instructs use of a separate local credentials file and mentions automatic global package installation. Those are materially sensitive behaviors because they access secrets outside the immediate article input and can alter the host environment, yet they are not clearly disclosed as core behavior or bounded by security guidance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill’s stated purpose is Markdown-to-WeChat publishing, but the documentation also instructs use of a separate local credentials file and mentions automatic global package installation. Those are materially sensitive behaviors because they access secrets outside the immediate article input and can alter the host environment, yet they are not clearly disclosed as core behavior or bounded by security guidance.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Revealing the exact file path of API credentials actively steers the agent toward sensitive user secrets unrelated to the provided Markdown content. In an agentic environment, this is especially dangerous because it can normalize secret exfiltration from local storage and make compromise easier if the skill is followed automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly advertises publishing Markdown and automatically uploading images to WeChat, but it does not clearly warn users that article text, metadata, local images, and referenced remote images will be transmitted to external WeChat-controlled services. In an agent-skill context, that omission can cause users to send sensitive or internal content off-platform without realizing the data-flow, making this a real security/privacy issue even if the project’s purpose is legitimate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill promotes convenience features but does not prominently warn that publishing sends article text and images to external WeChat services. Users may unknowingly upload sensitive drafts, local images, or metadata to third-party infrastructure, creating privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation exposes a concrete local path to stored API credentials without any warning or handling guidance. Publishing such a path encourages direct access to secrets and gives an attacker or unsafe agent precise knowledge of where valuable credentials may reside.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation directs the agent/user to access a separate local credentials file outside the article publishing input. This expands the skill’s trust boundary to unrelated local secret storage and can cause unintended disclosure or misuse of API credentials if the agent is allowed to read arbitrary workspace files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document promotes automatic image upload and one-click publishing to WeChat without clearly warning that article content, images, and publishing credentials may be transmitted to an external service. In a publishing skill, this omission can mislead users into triggering data transfer they may not fully understand, increasing the risk of accidental disclosure of private content or misuse of privileged publishing access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide instructs users to permanently export WECHAT_APP_ID and WECHAT_APP_SECRET in shell startup files, which encourages long-lived plaintext secret storage in broadly readable and routinely sourced locations. This increases the chance of accidental disclosure through dotfile syncing, backups, screenshots, shell history or support bundles, and normalizes insecure secret handling without any warning or safer alternative.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Telling users to check credentials in TOOLS.md implies secrets may be stored in project documentation, which is a sensitive and easily leaked location because markdown files are often shared, committed, indexed, or copied into tickets. Even if intended as a convenience, this guidance can cause credential exposure and poor secret hygiene across the skill workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically runs npm install -g @wenyan-md/cli if wenyan is missing, which expands its behavior from publishing content into installing and executing new software from an external package registry. This creates supply-chain and environment-modification risk: a compromised package, typosquatted dependency, or unexpected postinstall script could execute code with the user's privileges.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script scrapes WECHAT_APP_ID and WECHAT_APP_SECRET from $HOME/.openclaw/workspace/TOOLS.md, which is an unusual credential source and broadens the script's access to local secrets beyond direct user input. Even though the credentials are relevant to publishing, silently harvesting them from a workspace file increases secret exposure risk and trains users to store sensitive values in a markdown document that may be copied, synced, or committed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes a skill for publishing Markdown to the WeChat draft box with themes, code highlighting, and image upload. In this file, the implementation introduces an additional capability: scanning a user-specific documentation file under $HOME and extracting secret credentials from it, which is not implied by the publishing functionality itself. Credential loading may be necessary somewhere in the overall system, but reading arbitrary home-directory documentation content is a distinct capability beyond the stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script reads WECHAT_APP_ID and WECHAT_APP_SECRET from a user file and exports them into the current shell session. Although it prints success messages, it does not include any warning, comment, or user-facing disclosure that it is handling sensitive credentials and making them available as environment variables.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

SQP-3 applies to natural-language policy issues in any file type. The title and all user-facing instructions are presented only in Chinese for a publishing workflow, with no indication that users may choose another language or that the locale restriction is intentional and documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script description and subsequent user-facing messages are written in Chinese, which effectively imposes a specific language on users. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

All user-facing comments and messages in the script are written in Chinese, with no indication that another language is available or that Chinese is required for a documented regional reason. This can violate language/locale policy when skills force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.