Back to skill

Security audit

微信公众号文章抓取

Security checks for vulnerabilities and agentic risk

Overview

This skill needs Review because it ships and uses a hardcoded authenticated WeChat session cookie instead of safely relying on a user-provided credential.

Do not install or run this skill unless the hardcoded WeChat cookie has been removed, the exposed session has been revoked, and the script has been changed to read a user-provided secret from a protected location with clear warnings. As written, anyone with the package can see the bundled session credential, and users may unknowingly operate through someone else’s WeChat account session.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/wechat_article.py:18
Finding

Hardcoded WeChat Authentication Session Credentials

Content
View full analysis

Vulnerability Details

File Location: scripts/wechat_article.py:18-21 (credential declaration), with credential use at scripts/wechat_article.py:23-30, 35-52, 59-79, and 97-101
Vulnerability Type: Hardcoded authentication credentials and plaintext sensitive data
Risk Level: High

Vulnerable Code

The credential values below are redacted to prevent further disclosure. The source contains complete plaintext values for account and session-related cookie fields, including wxuin, data_ticket, slave_sid, slave_user, and wxtokenkey.

python
def load_cookie():
    """加载 Cookie"""
    cookie_str = """ua_id=REDACTED; wxuin=REDACTED; mm_lang=zh_CN; pac_uid=REDACTED; omgid=REDACTED; _qimei_uuid42=REDACTED; _qimei_fingerprint=REDACTED; _qimei_q36=; _qimei_h38=REDACTED; _clck=REDACTED; uuid=REDACTED; rand_info=REDACTED; slave_bizuin=REDACTED; data_bizuin=REDACTED; bizuin=REDACTED; data_ticket=REDACTED; slave_sid=REDACTED; slave_user=REDACTED; xid=REDACTED; _clsk=REDACTED; rewardsn=; wxtokenkey=777"""
    return cookie_str

The hardcoded credential is then used as the HTTP Cookie header:

python
def get_token(cookie):
    """获取 token"""
    headers = {
        "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36",
        "Cookie": cookie,
        "Referer": "https://mp.weixin.qq.com/"
    }
    r = requests.get("https://mp.weixin.qq.com/", headers=headers, allow_redirects=True)
    parsed = urlparse(r.url)
    params = parse_qs(parsed.query)
    return params.get('token', [None])[0]
python
cookie = load_cookie()

# 获取 token
print("🔑 获取 token...")
token = get_token(cookie)

Technical Analysis

The script embeds a complete authenticated WeChat session cookie directly in source code. Session fields such as data_ticket and slave_sid are bearer-style credentials: possession may be sufficient to make requests under the authe ...[truncated 2276 chars]

Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke all WeChat sessions associated with the exposed cookie and authenticate again to generate new credentials.
  2. Remove the cookie from the current source and all repository history, release archives, logs, caches, and deployed Skill copies.
  3. Replace load_cookie() with logic that reads a user-owned secret from the documented configuration file or a secret-management facility.
  4. Require restrictive file permissions, such as mode 0600, for any cookie file and reject files readable by other users where supported.
  5. Do not provide a fallback credential. Fail closed with a clear error when no user-supplied cookie is configured.
  6. Avoid exposing cookie or token values in exceptions, debug output, telemetry, or logs.
  7. Add secret scanning to pre-commit and continuous-integration workflows to detect session cookies and similar credentials before release.
  8. Keep configuration documentation synchronized with implementation and document secure credential rotation and revocation procedures.
  9. Where supported by WeChat, use a narrowly scoped, revocable authentication mechanism rather than a full browser session cookie.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior does not fully match the actual operational requirements: it relies on authenticated WeChat session cookies, but this sensitive credential handling is not clearly declared in the purpose or permission model. That mismatch is dangerous because users may be induced to provide live account credentials without understanding the trust boundary, account risk, or how those credentials may be used by the script.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script embeds a live authenticated WeChat cookie directly in source code, exposing session secrets to anyone who can read, copy, or redistribute the skill. That can enable unauthorized access to the associated WeChat account/session and makes credential compromise highly likely if the code is shared or logged.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill silently transmits a hardcoded authenticated cookie in outbound requests, causing users of the skill to operate with someone else's embedded credentials without informed consent. This can lead to unauthorized account use, session abuse, and accidental leakage of privileged access through logs, redistribution, or further automation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents functionality that inherently requires network access, but it does not declare any tool scope or permission boundary. This is dangerous because reviewers and runtime policy systems cannot accurately assess or constrain what the skill is allowed to do, increasing the chance of over-broad execution and unnoticed data egress.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions tell the user to manually extract a valid authenticated Cookie from mp.weixin.qq.com and store it locally, but they do not clearly warn that this is a sensitive session credential that can enable account access if exposed. In this skill context, that is especially risky because the cookie appears to be for a real logged-in publisher/admin session, so leakage through local files, logs, backups, or other tools could lead to unauthorized account use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code comments and variable naming claim cookies are loaded from a file, but the function actually returns an embedded credential. This misrepresentation increases the chance that reviewers or users will overlook the presence of sensitive hardcoded authentication data, worsening exposure and trust risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The request parameters force the locale to zh_CN, and the script's user-facing text is also entirely Chinese. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Tainted flow: 'params' from requests.get (line 32, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/wechat_article.py (reported line 52)May include surrounding context.

python
"Cookie": cookie,
        "Referer": "https://mp.weixin.qq.com/"
    }
    r = requests.get(url, params=params, headers=headers)
    data = r.json()
    
    if data.get("base_resp", {}).get("ret") == 0 and data.get("list"):

Tainted flow: 'params' from requests.get (line 32, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/wechat_article.py (reported line 79)May include surrounding context.

python
"Cookie": cookie,
        "Referer": "https://mp.weixin.qq.com/"
    }
    r = requests.get(url, params=params, headers=headers)
    data = r.json()
    
    if data.get("base_resp", {}).get("ret") == 0 and data.get("list"):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This API request explicitly sets lang to zh_CN, enforcing a specific locale. The file does not provide any opt-in, alternative locale handling, or justification for the forced language setting.

Content

No source excerpt is available for this finding.