Back to skill

Security audit

WeChat Channels Video Search

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it advertises, but it exposes the user's TikHub API token and search activity through normal debug output.

Review before installing. Use this only with a low-privilege TikHub token, avoid sensitive searches, and do not run this version where stdout or stderr is captured. Remove the token/debug prints and rotate any TikHub token used with this version in a logged environment.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/wechat_video_search.py:67
Finding

Bearer Token and Sensitive API Data Disclosed Through Debug Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wechat_video_search.py:26
Finding

Credential-Like Value Embedded in Source Code Comment

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (12)

Tainted flow: 'headers' from os.environ.get (line 58, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/wechat_video_search.py (reported line 69)May include surrounding context.

python
print("token",token)
    print("DEBUG: url=", url)
    try:
        resp = requests.get(url, headers=headers, timeout=60)
        print(f"DEBUG: status_code={resp.status_code}", file=sys.stderr)
        print(f"DEBUG: response_text={resp.text[:500]}", file=sys.stderr)
        resp.raise_for_status()

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill prints the TikHub API token, request URL, or portions of API responses, it can expose secrets and user query data to logs, terminals, screenshots, or downstream agents. This is especially dangerous because the token grants third-party API access and the search terms may contain sensitive investigative or personal information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script prints the full TikHub API token to stdout during normal execution with print("token", token). In agent, CI, or shared terminal contexts, stdout is often captured in logs, transcripts, or tool output, which can expose the credential to other users or systems and allow unauthorized API use.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Printing a sensitive API token without masking or warning is a direct secret exposure issue. Anyone with access to process output, shell history capture, notebook outputs, orchestration logs, or agent traces may recover the bearer token and impersonate the user against the third-party service.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill declares network, file-read, and environment-dependent behavior but does not declare any explicit tool scope or permissions. This weakens reviewability and containment: users and platforms cannot easily understand or restrict the skill’s access needs, increasing the chance of unintended data exposure or overly broad execution privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation instructs users to send both search keywords and an API token to a third-party service but does not clearly warn about privacy and data-sharing implications. Users may unknowingly transmit sensitive search terms, operational interests, or credentials to an external provider, creating confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/wechat_video_search.py (reported line 16)May include surrounding context.

python
from urllib.parse import quote

# API 端点(中国大陆使用新域名)
TIKHUB_SEARCH_URL = "https://api.tikhub.dev/api/v1/wechat_channels/fetch_search_latest"


def load_config():

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The requests.get call sends the search keyword in the URL query string and the API token in the Authorization header to api.tikhub.dev. For a code file, external transmission of user data and credentials should have some visible disclosure, but the script provides no prompt or user-facing warning before making the network request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The user-facing natural-language fields are written only in Chinese, which imposes a specific language/locale without indicating user choice or a justified region-specific constraint. The policy requires either an explicit language choice for users or clear documentation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This is a markdown file, so missing user warnings apply when the description omits warnings about behaviors affecting user data, privacy, or system integrity. The usage and API sections explain how to send keywords to a third-party service and retrieve video download links, but they do not disclose that user queries are transmitted externally or note any caution around handling returned media links.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The description states the skill requires bypassing network restrictions, and later notes prescribe a China-mainland-specific domain choice. This imposes a locale/network constraint without offering user choice or clearly framing it as an optional region-specific instruction.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest description states the skill's general capability but does not define specific invocation phrases, scope limits, or exclusion conditions. In manifest files, missing trigger specificity can lead to overly broad or unintended activation if the host system uses the description for routing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.