Back to skill

Security audit

WeChat Article to Obsidian

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its WeChat-to-Obsidian purpose, but its fetch scripts accept arbitrary URLs/resources instead of enforcing WeChat-only access.

Review this before installing. Use it only with trusted https://mp.weixin.qq.com article links, and prefer a version that enforces a WeChat host allowlist and HTTPS-only redirects in every fetcher. Set vault_disk_root carefully because the skill will create folders and write Markdown files inside that vault.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch.sh:8
Finding

Unrestricted URL Fetching Enables SSRF and Local Resource Access

Content
View full analysis
'); process.exit(1); } ``` ```javascript await page.goto(url, { waitUntil: 'domcontentloaded', timeout: 45000 }); ``` #### `SKILL.md:96-106` ```bash SKILL_PATH="" # Step 1: Fetch HTML (fast path) bash "$SKILL_PATH/scripts/fetch.sh" "URL" /tmp/wx_article.html # Step 2: Inspect metadata node "$SKILL_PATH/scripts/parse.mjs" /tmp/wx_article.html --json # Step 3: If title/contentLength is empty or unusable, run browser fallback python3 "$SKILL_PATH/scripts/fetch-browser.py" "URL" /tmp/wx_article.html node "$SKILL_PATH/scripts/parse.mjs" /tmp/wx_article.html --json ``` ## ...[truncated 3357 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code is related to WeChat article extraction, so it is in the same general domain, but it does not accurately match the declared description. The description promises a zero-extra-dependency skill using only curl and Node.js to save articles as clean Markdown notes in Obsidian, potentially in batch. The actual code is a Python script that depends on Playwright and Chrome/Chromium, fetches and renders the page in a headless browser, extracts fields, and writes an HTML file. There is no Markdown conversion, no Obsidian integration, and no batch logic in this chunk. This is a material description/behavior mismatch, not just an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code chunk is a simple fetch helper that downloads HTML from a supplied URL. While fetching article HTML could be a supporting step toward the declared purpose, the declared description presents a complete skill for saving WeChat articles as clean Markdown notes in Obsidian. The supplied code does not implement the core promised behavior: no WeChat-specific processing, no content extraction, no Markdown generation, no Obsidian output, and no batch workflow. Therefore the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
The bundled `save.mjs` uses a strict safe save path:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill instructs use of shell commands and direct file writes, but it does not declare any tool scope or permission boundaries. This increases the chance the runtime grants broader-than-necessary capabilities or that reviewers and users misunderstand the skill's effective privileges, which is risky for a skill that fetches remote content and writes into a local vault.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description explicitly limits dependencies to curl and Node.js, but the skill documentation later instructs use of python3 and lists Playwright plus a Chromium/Chrome browser as dependencies for fallback mode. This is a semantic mismatch about what the skill actually needs to perform its advertised article-fetching behavior in some cases.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The browser page is created with a hard-coded locale of 'zh-CN', which imposes a specific language/locale behavior on all users. This file does not offer any user opt-in or configuration path, and the locale constraint is not justified in the visible documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script hard-codes locale="zh-CN" when creating the browser page. That is a natural-language/locale policy concern because it imposes a specific locale without any visible user opt-in or explanation that the skill is restricted to a China-specific context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest explicitly advertises 'safe direct-write saving inside the configured vault root' but does not clearly warn that the skill modifies local files on disk. In a skill that fetches external article content and writes notes automatically, lack of explicit disclosure and confirmation can lead to users unknowingly authorizing local filesystem changes, increasing the risk of unintended data modification or clutter.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list contains generic phrases such as '保存微信', '导入微信', 'save wechat', and 'wechat article' that can match broad conversational context and cause the skill to activate when the user did not explicitly intend to run a file-writing workflow. In this skill’s context, unintended activation is more concerning because the described capability includes fetching remote content and saving directly into a local Obsidian vault, turning a prompt-matching error into an unintended local side effect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file applies to SQP-2, and the usage section encourages the agent to save content into the user's vault automatically. While the behavior is described, there is no clear user-facing warning that the skill will create folders and write Markdown files on disk, which affects user data and system state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown explains the fetch workflow, including curl and browser-based retrieval, but it presents this operationally rather than as a user-facing warning about network access and data transmission. Because the skill sends user-provided URLs and retrieves remote content, the description should explicitly disclose that it performs external network requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown describes writing user answers to config.json and later saving Markdown files directly under vault_disk_root, but it does not frame these as user-impacting file writes with a clear warning. Since the skill modifies local files persistently, the description should disclose that behavior explicitly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script hard-codes an Accept-Language header preferring zh-CN and zh, which imposes a locale preference regardless of the user's settings or intent. This is a natural-language policy issue because it forces a specific language behavior without offering a choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.