Back to skill

Security audit

WeChat Official Account (公众号发文)

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-built for WeChat publishing, but its browser mode uses broad authenticated-page access and model-driven automation in ways users should review carefully before installing.

Review browser mode carefully before installing. Prefer API mode when possible; avoid configuring external analyzer API keys unless you accept that authenticated WeChat page data may leave your machine; use a local analyzer endpoint if needed; remove clipboard permissions; avoid --debug and --step on sensitive accounts; and clear ~/.openclaw/wechat-mp-browser plus generated debug files when finished.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/page_analyzer.py:20
Finding

Authenticated Administration Page HTML Is Sent to External LLM Services with Incomplete Redaction

Content
View full analysis
str: """脱敏:移除 script/style、常见 token 模式,压缩空白。""" html = re.sub(r"]*>[\s\S]*?", "", html, flags=re.IGNORECASE) html = re.sub(r"]*>[\s\S]*?", "", html, flags=re.IGNORECASE) for pat, repl in _TOKEN_PATTERNS: html = pat.sub(repl, html) html = re.sub(r"\s+", " ", html).strip() return html def _get_page_summary(page) -> str: """获取页面内容摘要:URL + 脱敏后的简化 HTML。""" try: url = page.url html = page.content() html = _sanitize_html(html) if len(html) > MAX_HTML_CHARS: html = html[:MAX_HTML_CHARS] + "\n...[已截断]" return f"URL: {url}\n\nHTML(简化):\n{html}" except Exception as e: return f"获取页面失败: {e}" ``` ```python client = OpenAI(api_key=key or "ollama", base_url=url) try: resp = client.chat.completions.create( model=model, messages=[{"role": "user", "content": prompt}], temperature=0.1, ) ``` ```python page_content = _get_page_summary(page) prompt = ANALYZER_PROMPT.format(page_content=page_content) if context: prompt = f"上下文:{context}\n\n{prompt}" raw = _call_openai(prompt, api_key, base_url) ``` ### Technical Analysis Browser mode captures the complete DOM seri ...[truncated 2386 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/publish_browser.py:313
Finding

Untrusted Page Content Can Influence Model-Driven Browser Navigation and Clicks

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/publish_browser.py:280
Finding

Persistent Browser Context Receives Unnecessary Clipboard Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/publish_browser.py:39
Finding

Debug and Step Modes Persist Unsanitized Authenticated Pages and Screenshots

Content
View full analysis
None: out_dir.mkdir(parents=True, exist_ok=True) path = out_dir / f"step-{step_num:02d}-{step_name}.png" try: page.screenshot(path=str(path)) print(f"[步骤 {step_num}] 截图已保存: {path}", file=sys.stderr) except Exception as e: print(f"截图失败: {e}", file=sys.stderr) ``` ```python if args.debug: (Path.home() / ".openclaw").mkdir(parents=True, exist_ok=True) (Path.home() / ".openclaw" / "wechat-page-check.html").write_text( page.content(), encoding="utf-8" ) ``` ```python if args.debug: try: page.screenshot(path=str(Path.home() / ".openclaw" / "wechat-debug.png")) (Path.home() / ".openclaw").mkdir(parents=True, exist_ok=True) (Path.home() / ".openclaw" / "wechat-debug.html").write_text( page.content(), encoding="utf-8" ) except Exception: pass ``` ### Technical Analysis When `--debug` or `--step` is enabled, the Skill saves complete, unsanitized browser HTML and screenshots under `~/.openclaw`. These artifacts can include authenticated administration content, article drafts, account identifiers, hidden fields, session-related values, or login QR codes. The code does not explicitly set restrictive file permissions, warn about the sensitivity of each capture, sanitize HTML before storage, exclude authentication screens, or remove the files after the run. The artifacts may therefore outlive the browser session and enter backups, synchronization services, or diagnostic archives. ### Attack Path 1. A user enables `--debug` or `--step` while diagnosing browser automation. 2. The browser reaches a login page, authenticated dashboard, or ...[truncated 766 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Dependencies Are Installed Without Upper Bounds, Locking, or Integrity Hashes

Content
View full analysis
=1.40.0 openai>=1.0.0 ``` ### Technical Analysis The dependency declarations specify only minimum versions. A fresh installation may therefore resolve any future release of `playwright` or `openai`. No lock file or package hash is present to make installations reproducible or verify artifact integrity. The package names are legitimate, and the audit found no evidence of typosquatting or an intentionally malicious dependency. The risk arises from unrestricted future resolution, package-index compromise, dependency compromise, and unreviewed breaking or security-sensitive changes. Both dependencies execute with the invoking user's privileges. Playwright also installs and controls a browser, while the OpenAI client handles API keys and externally transmitted page data. ### Attack Path 1. A user runs `pip install -r requirements.txt`. 2. The package resolver selects the newest versions satisfying the lower bounds. 3. A future compromised, malicious, or incompatible release is available from the configured index. 4. The package is downloaded without verification against a reviewed lock file or expected hash. 5. Package installation or runtime code executes with the user's privileges and gains access to the Skill's environment, browser profile, API keys, and data. ### Impact Assessment A compromised dependency could obtain the same privileges as the Python process, including access to environment variables, local files available to the user, the persistent browser profile, and network connectivity. There is no evidence that this has occurred in the reviewed artifact. The finding concerns preventable supply-chain exposure and build non-reproducibility. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The core declared purpose partly matches: the script does create a draft and optionally publish a WeChat Official Account article via API. However, the description materially overstates capabilities. The supplied code only supports direct API usage with WECHAT_APPID/WECHAT_SECRET, which aligns with service-account-style API access, but it contains no browser automation, no QR-based interactive login, no page HTML login detection, and no scheduling mechanism. Thus the description does not accurately represent the full claimed behavior of the provided code chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises capabilities that involve environment variables, filesystem access, and network use, but it does not declare any explicit tool scope such as permissions or allowed-tools. In a skill that can publish content and optionally send page HTML to an external LLM, missing scope boundaries increases the chance of over-broad execution and unintended access to sensitive data or network destinations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The analyzer captures the WeChat backend page URL and HTML, then sends that content to an external LLM endpoint for decision-making. Because this skill operates on an authenticated publisher dashboard, the HTML can contain account metadata, article contents, login state, internal links, and other sensitive business data; the current sanitization only strips a few token patterns and does not prevent broader data leakage.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function forwards the full page URL and a large sanitized HTML snapshot to the model, but the redaction is narrow and pattern-based. Sensitive information can still appear in article text, account names, unpublished drafts, embedded identifiers, navigation state, and other natural-language or structural content that the regexes do not remove, enabling substantial data leakage from an authenticated admin surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code transmits page-derived content to an external LLM API without any user-visible warning, consent flow, or indication that authenticated WeChat backend data may leave the local environment. In the context of a publishing/admin skill, this makes accidental exfiltration of sensitive operational content more dangerous because users may reasonably assume browser automation stays local.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file description and runtime targets a fixed Chinese-language WeChat environment, including Chinese-only usage context and later hardcoded zh_CN URLs/selectors, without offering any language or locale choice. This is a natural-language locale policy issue because the skill assumes a specific language/locale rather than making it optional or explicitly user-selected.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The script uses a persistent browser profile directory under the user's home directory, which preserves authenticated WeChat session data across runs. While this improves usability, it also means tokens, cookies, and other session artifacts remain on disk and could be reused by other local processes or users if the directory permissions are weak or the host is compromised.

Content

Scanner excerpt · scripts/publish_browser.py (reported line 227)May include surrounding context.

python
def main() -> int:
    parser = argparse.ArgumentParser(
        description="Create WeChat Official Account draft via browser (model-driven)"
    )
    parser.add_argument("--title", help="Article title (≤32 chars)")
    parser.add_argument("--content", help="Article body (Markdown or HTML)")

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The browser context explicitly requests clipboard-read and clipboard-write permissions even though creating and publishing WeChat articles does not require clipboard access. If the automated browser session visits unexpected or attacker-controlled content, that page could read sensitive clipboard contents or overwrite the clipboard, increasing the risk of credential or data exposure.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is specified with only a lower bound, which allows future major or minor versions of Playwright to be installed without review. This can introduce breaking changes or a compromised/upstream-vulnerable release into an automation skill that interacts with browser sessions and authenticated WeChat accounts, increasing supply-chain risk.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
playwright>=1.40.0
openai>=1.0.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The OpenAI package is also unpinned and may resolve to any newer release, including versions with incompatible API behavior or newly introduced vulnerabilities. In a skill that may process article content, credentials, and publishing workflows, uncontrolled dependency upgrades increase supply-chain and operational security risk.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
playwright>=1.40.0
openai>=1.0.0

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring states '无硬编码,由模型根据页面内容动态决策' ('no hardcoding; the model dynamically decides based on page content'), but the implementation hardcodes both a default provider endpoint and a default model at L054-L055. That documentation overstates the absence of hardcoded behavior and contradicts the actual implementation choices.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The embedded analyzer prompt is entirely in Chinese and is tailored to return Chinese-language reasoning without any indication that the user can choose another language. This is a natural-language locale constraint present in the file and is not documented as an opt-in or region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file description and usage indicate the skill is specifically for publishing 公众号 articles, with examples and constraints written only for that locale-specific platform and workflow. The instructions do not offer user opt-in or an alternative language/locale path, which can violate a language/locale choice policy when the restriction is not explicitly presented as optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This file contains user-facing natural language exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this locale. Per the policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.