Back to skill

Security audit

WeWe RSS 文章读取

Security checks for vulnerabilities and agentic risk

Overview

The skill’s article-reading workflow is coherent, but it needs review because it can access local WeWe RSS data and instructs the agent to retrieve an AUTH_CODE from a .env file without secret-handling rules.

Install only if you are comfortable with the agent reading your local WeWe RSS configuration, subscription database, cached article content, and localhost service responses. Do not let the agent print or paste AUTH_CODE or the full .env file; prefer confirming the variable exists or providing a redacted status instead. Review the separate wewe-rss-deploy skill before allowing automatic deployment.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:199
Finding

Unrestricted Access to an Authentication Secret in the Environment File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 199–207
Vulnerability Type: Sensitive credential access without disclosure controls
Risk Level: Medium

Relevant instruction excerpt (English translation):

markdown
4. **AUTH_CODE**: If the API returns 401, check the `AUTH_CODE` configuration in `.env`.

| Error | Cause | Resolution |
|------|------|----------|
| API returns 401 | AUTH_CODE is required | Obtain AUTH_CODE from `.env` |

Technical Analysis

The Skill instructs the Agent to retrieve AUTH_CODE directly from the WeWe RSS .env file when the local API returns HTTP 401. Environment files commonly contain authentication credentials and other unrelated secrets. Reading such a file places its contents within the Agent's execution context, where they may be exposed through generated responses, tool logs, debugging output, or conversation history.

The instruction does not define least-privilege handling requirements, limit access to the specific variable through a protected interface, prohibit displaying the value, or require redaction. Although the audited file does not explicitly instruct the Agent to transmit the credential externally, unrestricted retrieval of a plaintext authentication secret creates an avoidable credential-exposure risk.

Attack Path

  1. The WeWe RSS endpoint returns HTTP 401, either because authentication is enabled, the request omits credentials, or the service is configured to reject the request.
  2. The Agent follows the troubleshooting instructions in SKILL.md.
  3. The Agent opens the WeWe RSS .env file and retrieves AUTH_CODE.
  4. The secret enters the Agent's context and may subsequently appear in command output, diagnostic logs, conversation history, or a user-facing response.
  5. A party with access to those records could reuse the exposed value to authenticate to services protected by the same credential.

No external exfiltration, privilege ...[truncated 656 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction directing the Agent to open .env and retrieve the plaintext credential.
  2. Ask the user or administrator to verify that AUTH_CODE is configured without revealing its value.
  3. Supply credentials through a dedicated secret manager or protected environment-variable interface that does not expose the secret to conversational output.
  4. If the Agent must use the value, retrieve only the named variable rather than reading the complete .env file.
  5. Explicitly prohibit printing, logging, returning, or persisting the credential.
  6. Redact authentication headers and secret values from tool output, exceptions, and debugging logs.
  7. Use a narrowly scoped credential, rotate it after suspected exposure, and avoid reusing it for other services.
  8. Prefer a health-check or authentication-status endpoint that can diagnose HTTP 401 responses without requiring the Agent to inspect secret-bearing files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger condition is broad enough that the skill may activate for general requests about WeChat public account content without strong scoping or confirmation. In an agent setting, overbroad activation can cause unintended access to local services, local files, and previously cached article content the user did not explicitly ask the agent to inspect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill instructs the operator to check AUTH_CODE in a local .env file but does not clearly treat it as a secret or prohibit exposing it in outputs. In an agent workflow, this increases the risk that the model retrieves, echoes, logs, or mishandles a local authentication credential while troubleshooting API access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.