Back to skill

Security audit

AWS WeChat Article Formatting

Security checks for vulnerabilities and agentic risk

Overview

The package includes a local WeChat article formatter, but its instructions also cover web search, AI image work, WeChat account secrets, uploads, and draft publishing while claiming no network or credentials.

Review this before installing if you only wanted a local formatter. Use it only with explicit limits: run the local Python formatter for Markdown-to-HTML conversion, do not provide WeChat app secrets, and do not allow web search, uploads, draft creation, or account switching unless you intentionally want those publishing capabilities and approve each action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented behavior is internally inconsistent: it markets itself as a local formatter, but also describes writing, search, image generation, and embed-card behavior not cleanly represented in the stated scope. Description-behavior mismatches are dangerous because users and orchestrators may grant trust or permissions based on the benign description while the skill steers into broader actions.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad enough to match common writing and editing requests, increasing the chance that the skill activates outside its narrow intended purpose. Overbroad routing is risky here because the skill text contains expanded workflows that include search, generation, and publishing guidance.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file explicitly claims 'zero network, zero credentials' but later documents network search and credential-based WeChat account and publishing operations. This contradiction can mislead users and safety systems into treating the skill as low risk when it actually includes high-trust workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill document broadens from local Markdown formatting into article writing, web search, image generation, and WeChat publishing. This is a scope-creep vulnerability because a seemingly harmless formatting skill can become a gateway to higher-risk actions, including external communication and content publication.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Including credentialed account management and draft/material publishing instructions in a formatting skill is unsafe because it normalizes access to secrets and outbound publication under an unrelated feature banner. If an agent follows these instructions, it could handle credentials or publish content without the user appreciating that this formatter has escalated into account operations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill does not declare a restrictive tool scope, yet the documentation instructs reading and writing files and later expands into networked and credentialed operations. In an agent environment, missing explicit scope makes it easier for the skill to be invoked with broader capabilities than users would reasonably expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The condition 'when the user asks to write a WeChat article' is too broad for a skill whose safe core is local formatting. Ambiguous activation can route general writing tasks into a skill that also documents network search, image generation, and publication, increasing the chance of unintended higher-risk actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file mandates a fixed “刘润风” writing style as part of the skill’s writing behavior, without indicating that users can choose another language/style preference. This is a natural-language policy concern because it imposes a specific stylistic/locale choice by default rather than offering opt-in or alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest uses Chinese for the display name and all usage guidance, which can impose a language requirement on users or downstream editors without any opt-in or justification. Under the policy, forcing a specific language is a natural-language policy concern unless the locale constraint is explicit and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill’s display name and all user-facing guidance are written entirely in Chinese, with no indication that language selection is optional or limited to a justified region-specific context. This can violate language/locale policy because it effectively constrains use to a single language without offering user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This manifest uses Chinese for the display name and all user-facing descriptive fields, but it does not document that the skill is Chinese-only or offer any language/locale choice. That can violate language/locale policy when users or systems expect locale-neutral or user-selectable behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file uses Chinese for the display name, usage guidance, anti-patterns, and example content, which effectively forces a specific language/locale for users or downstream maintainers. The policy allows locale constraints only when they are explicitly justified or when users are given a language choice, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description at L05 forces a specific language/locale presentation without any indication that users can choose another language. Under the policy, language constraints should be optional or clearly justified; this manifest provides neither.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest requests shell access for a skill whose stated purpose is article formatting and HTML conversion, which does not inherently require command execution. Unnecessary shell capability materially increases the attack surface because prompt-controlled or content-driven workflows could invoke OS commands, leading to arbitrary command execution, data access, or environment compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The display name is specified only in Chinese ("要点清单"), which indicates a fixed language choice in user-facing text. Under the policy, forcing a specific language without offering a user choice or documenting a justified locale constraint is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill documentation is presented only in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file uses Chinese-only natural-language values for the theme name and description. Because this is a general theme preset rather than a clearly region-specific artifact, forcing a single language without opt-in can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file uses Chinese-only natural-language values for the theme name and description. Because this is a generic theme preset rather than an explicitly region-specific artifact, the file imposes a specific language with no opt-in or alternative locale support, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This manifest file contains natural-language fields for the theme name and description exclusively in Chinese. Because the file does not indicate that the theme is region-specific or provide an opt-in language choice, it may violate a language/locale policy requiring user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This YAML theme file uses Chinese-only naming and descriptive text such as the skill name and description, which indicates a fixed language/locale choice. The file does not offer any user opt-in or explain that the preset is intentionally region- or language-specific, so it may conflict with language-choice policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The theme name, description, and font stack explicitly target Chinese typography, including 'Songti SC' and 'Noto Serif CJK SC', indicating a fixed language/locale preference. The file does not offer any language choice or explain that this preset is intentionally region-specific, which can conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.