Wechat Xhs Publisher

Security checks across malware telemetry and agentic risk

Overview

The skill does what it says, but it can publish to public social accounts and mark rewritten news as original without a clear final user approval step.

Review carefully before installing. Use it only with trusted WeChat, Xiaohongshu, image-generation, and IP-checking tools; require a preview and explicit confirmation before any upload or post; verify the active accounts; and confirm originality/copyright compliance instead of automatically marking rewritten news as original.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description is broad enough that ordinary requests about trending news, article drafting, or social media posting could unintentionally invoke a workflow that rewrites content, generates images, checks IPs, and publishes externally. In a skill with real external side effects, overbroad activation increases the chance of accidental data disclosure or unintended posting to public platforms.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill performs outbound transmission of article text and images to external services, including image-generation APIs, WeChat, Xiaohongshu, and an IP lookup site, but the description does not clearly warn users that their content and metadata will leave the local environment. This creates a meaningful risk of unintended sharing of sensitive, proprietary, or unpublished material.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal