Back to skill

Security audit

Uni App Wechat Cicd

Security checks for vulnerabilities and agentic risk

Overview

This CI/CD skill is purpose-aligned, but it handles WeChat publishing credentials and release actions with weak scoping and cleanup safeguards.

Install only if you are comfortable giving the workflow authority to upload WeChat Mini Program builds. Use protected branches and manual approvals for review/release, pin dependencies and use npm ci, keep WeChat keys only in CI secret stores, write keys to temporary confined paths, delete them after use, and avoid passing private keys through reusable artifacts or arbitrary WEAPP_PRIVATE_KEY_PATH values.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/build-uni.js:23
Finding

Unrestricted Private-Key Path Allows Arbitrary File Overwrite

Content
View full analysis
"$KEY_PATH" chmod 400 "$KEY_PATH" echo " 私钥已写入: $KEY_PATH" ``` ### Technical Analysis Both publishing scripts accept `WEAPP_PRIVATE_KEY_PATH` directly from the environment and use it as a filesystem destination without validating or confining it to the project workspace. The Node.js implementation creates missing parent directories recursively and then calls `fs.writeFileSync`, which truncates an existing file by default. The shell implementation similarly creates the parent directory and overwrites the selected file through shell redirection. Absolute paths and traversal paths such as `../../target-file` are not rejected. Consequently, anyone able to influence the environment of the publishing process can overwrite any file writable by the account running the CI job or local script. ### Attack Path 1. An attacker compromises a CI variable, modifies an unprotected pipeline configuration, or otherwise controls the environment used to invoke the publishing script. 2. The attacker sets `WEAPP_PRIVATE_KEY_PATH` to a sensitive writable location, such as a workspace configuration file or a user-owned startup/co ...[truncated 1075 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ci-publish.sh:47
Finding

WeChat Publishing Private Key Persists on Disk After Execution

Content
View full analysis
"$KEY_PATH" chmod 400 "$KEY_PATH" echo " 私钥已写入: $KEY_PATH" ``` `references/cicd-templates.md:51-55` ```yaml - name: Prepare private key run: | mkdir -p keys echo "${{ secrets.WEAPP_PRIVATE_KEY }}" > keys/private.key chmod 400 keys/private.key ``` No corresponding `finally`, shell `trap`, post-job cleanup step, or explicit key deletion is implemented. ### Technical Analysis The scripts transform a CI secret into a plaintext private-key file required by `miniprogram-ci`. Although the shell implementation changes the file mode to `0400`, the file remains present after successful execution and after most failure paths. The Node.js implementation does not set an explicit file mode when calling `fs.writeFileSync`; its resulting permissions therefore depend on the process umask and preexisting file permissions. Neither implementation guarantees deletion of the key. This is especially risky on persistent runners, developer workstations, reused Jenkins workspaces, or systems where workspace content is backed up, archived, inspected, or made available to later jobs. ### Attack Path 1. A legitimate publishing job writes `WEAPP_PRIVATE_KEY` to the configured key path. 2. The job succeeds o ...[truncated 930 chars]
Remediation
View remediation
"$KEY_PATH" ``` - In Node.js, wrap publishing in `try/finally` and remove the generated file in the `finally` block. - Create the file with an explicit restrictive mode such as `0600`. - Avoid logging unnecessary details about where long-lived credentials are stored. - Use ephemeral CI runners where possible. - Exclude key directories from source control, build artifacts, caches, backups, and diagnostic bundles. - Add an explicit cleanup step with `if: always()` in GitHub Actions and equivalent post-job cleanup in other CI systems. - Rotate the WeChat publishing key if it may already have persisted on a shared or reused runner. ]]>

T08 · Insecure Dependencies

Warning
Location
references/cicd-templates.md:129
Finding

GitLab Deployment Template Installs an Unpinned Dependency at Runtime

Content
View full analysis
keys/private.key - node scripts/build-uni.js ``` ### Technical Analysis The deployment template runs: ```bash npm install --save-dev miniprogram-ci ``` during every deployment. No exact version is specified, so npm may resolve a newer package release than the version previously reviewed or tested. This also mutates dependency metadata during the deployment job instead of strictly consuming a committed lockfile. Because npm packages can run lifecycle scripts during installation, dynamically resolving a dependency in a credential-bearing deployment job increases supply-chain exposure. A compromised upstream release, account takeover, or unexpected incompatible update could execute code with access to the repository, job environment, and publishing credentials. The audit found no evidence that the named package is malicious. The vulnerability is the unsafe installation pattern and lack of reproducibility. ### Attack Path 1. An upstream package release or one of its transitive dependencies is compromised or unexpectedly changed. 2. A GitLab deployment job starts and resolves the current package version using the unpinned `npm install` command. 3. npm downloads and installs the newly resolved code, potentially running package lifecycle scripts. 4. The installed code executes in the deployment environment. 5. It may access source files, environment variables, generated private-key files, and network resources available to the CI job. 6. The compromised dependency may steal publishing credentials or tamper with the build before `build-uni.js` uploa ...[truncated 636 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README explicitly promotes automated build, upload, and publishing flows to WeChat/GitHub/GitLab CI, but it does not warn users that running these workflows can transmit source code and build artifacts to external platforms or change release state. In a CI/CD skill, those side effects are expected, but omitting disclosure and gating guidance increases the chance that a user triggers publication or code upload without understanding the consequences.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill includes shell and environment-driven CI/CD workflows but does not declare any tool scope or allowed-tools boundary. In an agent setting, that omission can let the agent invoke broader shell/env capabilities than the skill explicitly signals, increasing the chance of unintended command execution or secret exposure during build and release steps.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to move a WeChat private key through CI/CD and artifacts, but it does not prominently warn that this credential can authorize code uploads and release actions if mishandled. In practice, weak guidance around key storage, artifact handling, masking, and release approvals can lead to credential leakage or unauthorized mini-program publication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file applies to SQP-3, which covers natural-language policy violations. The title and all user-facing instructions are in Chinese, and the document does not indicate that Chinese is optional, selectable, or required for a region-specific audience, which can amount to forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions, headings, and operational guidance only in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/miniprogram-ci.md (reported line 211)May include surrounding context.

md
run: |
    mkdir -p keys
    echo "${{ secrets.WEAPP_PRIVATE_KEY }}" > keys/private.key
    chmod 600 keys/private.key

env:
  WEAPP_APPID: ${{ secrets.WEAPP_APPID }}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script writes the WeChat mini-program private key from an environment variable to a filesystem path and does not remove it afterward. In CI/CD environments, files can persist in workspaces, artifacts, caches, or shared runners, increasing the chance of credential exposure beyond the job lifetime.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cicd-templates.md (reported line 60)May include surrounding context.

md
echo "🔑 Step 2/4 - 写入私钥..."
mkdir -p "$(dirname "$KEY_PATH")"
echo "$PRIVATE_KEY" > "$KEY_PATH"
chmod 400 "$KEY_PATH"
echo "   私钥已写入: $KEY_PATH"

# Step 3: 构建 uni-app

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/ci-publish.sh (reported line 53)May include surrounding context.

sh
echo "🔑 Step 2/4 - 写入私钥..."
mkdir -p "$(dirname "$KEY_PATH")"
echo "$PRIVATE_KEY" > "$KEY_PATH"
chmod 400 "$KEY_PATH"
echo "   私钥已写入: $KEY_PATH"

# Step 3: 构建 uni-app

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The upload description uses toLocaleString('zh-CN'), which forces a specific locale in generated natural-language metadata. This is a natural-language policy issue because the script does not offer a language or locale choice or document why Chinese locale is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and all user-facing status/error messages are in Chinese, with no indication that language is configurable or limited to a China-specific audience. This can violate a language/locale policy when organizational tooling should not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.