Back to skill

Security audit

bozo-wechat-publisher

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a real WeChat draft publisher, but it uses unsafe installation and credential/file-upload patterns that users should review before installing.

Install only if you are comfortable granting this skill access to your WeChat official account credentials and sending article content and images to WeChat. Avoid the curl-to-sudo-bash setup, do not store AppSecret in shell startup files, review any Markdown cover paths before publishing, and prefer a pinned, manually installed wenyan-cli with credentials supplied only for the specific publishing command.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (7)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:261
Finding

Privileged execution of a mutable remote installation script

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/publish-card-theme-v2.sh:42
Finding

Automatic installation of an unpinned global npm dependency

Content
View full analysis
/dev/null; then print_error "wenyan-cli is not installed." npm install -g @wenyan-md/cli fi } ``` The English message above represents the original informational error text; the security-relevant command is unchanged. ### Technical Analysis If `wenyan` is unavailable, the publication scripts automatically install the latest registry version of `@wenyan-md/cli` globally. The dependency is not pinned to an audited version, no integrity value or lockfile is supplied, and publication itself implicitly authorizes installation. npm packages can execute lifecycle scripts during installation. The installed program is subsequently used to process article files and, in the main publishing workflow, operates in an environment containing WeChat credentials. A future compromised release, registry-account takeover, or malicious transitive dependency could therefore introduce code that was not included in the audited project. ### Attack Path 1. The user invokes a publishing script on a system where `wenyan` is absent. 2. The script runs `npm install -g @wenyan-md/cli` without confirmation. 3. npm resolves the latest package and transitive dependency versions. 4. Package lifecycle code executes during installation. 5. The installed CLI is then invoked to process user content and may inherit publishing credentials from the environment. 6. A compromised package can read files, steal credentials, modify the host, or send data to arbitrary endpoints. ### Impact Assessment Exploitation provides arbitrary code execution with the pr ...[truncated 279 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/publish-card-theme-v2.sh:177
Finding

Unrestricted cover path can upload arbitrary readable local files

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/publish-card-theme-v2.sh:48
Finding

Implicit credential extraction from the Agent workspace

Content
View full analysis
/dev/null | head -1 | sed 's/.*export WECHAT_APP_ID=//' | tr -d ' "' || echo "") export WECHAT_APP_SECRET=$(grep "export WECHAT_APP_SECRET=" "$TOOLS_MD" 2>/dev/null | head -1 | sed 's/.*export WECHAT_APP_SECRET=//' | tr -d ' "' || echo "") fi fi } ``` The original status message is non-English; it is translated above without changing executable behavior. The referenced path is: ```bash TOOLS_MD="$HOME/.openclaw/workspace/TOOLS.md" ``` ### Technical Analysis When credentials are absent from the environment, the Skill silently searches a general OpenClaw workspace file and extracts values matching credential-export syntax. This crosses a trust boundary between the publishing task and broader Agent workspace state. A publishing Skill only needs credentials explicitly supplied for the current account and operation. Automatically inspecting shared Agent documentation is not necessary and can unexpectedly expose secrets stored for other workflows. Exporting the values also makes them available to subsequently launched child processes. ### Attack Path 1. WeChat environment variables are unset. 2. The user invokes one of the publishing scripts. 3. The script automatically opens `$HOME/.openclaw/workspace/TOOLS.md`. 4. Matching AppID and AppSecret values are extracted and exported. 5. Subsequent tools and publishing su ...[truncated 535 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/publish-curl.sh:85
Finding

WeChat AppSecret is placed in URL query strings

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/publish-curl.sh:259
Finding

Unsafe JSON construction from attacker-influenced Markdown fields

Content
View full analysis
"$json_payload" << EOF { "articles": [ { "title": "$title", "author": "${author:-}", "content": "$(echo "$content" | sed 's/"/\\"/g' | tr -d '\n')", "thumb_media_id": "$thumb_media_id", "content_source_url": "${source_url:-}" } ] } EOF ``` ### Technical Analysis The script constructs JSON by interpolating frontmatter and Markdown content into a shell heredoc. Only double quotes in the content are escaped. Existing backslashes, tabs, carriage returns, control characters, and special values in `title`, `author`, and `source_url` are not serialized safely. Escaping a quote without first escaping backslashes is insufficient because attacker-controlled backslashes can alter how the resulting quote is interpreted. Frontmatter fields receive no JSON escaping at all. The script checks for `jq` earlier but does not use it to build the payload. This can produce malformed JSON or allow supplied content to alter adjacent JSON fields and structures. ### Attack Path 1. An attacker supplies a Markdown file with specially crafted frontmatter or body text containing JSON metacharacters and backslash sequences. 2. The script extracts those values without robust validation. 3. Shell interpolation places the values directly into the JSON heredoc. 4. Incomplete escaping changes the meaning or validity of the resulting JSON document. 5. The manipulated payload is sent to the WeChat draft endpoint. ### Impact Assessment An attacker can corrupt the publication request, cause denial of service for the publishing workflow, or manipulate draft fields represented by the generated JSON. The direct impact is limited to the payload submitted under the user's WeChat credential; this issue does not independe ...[truncated 149 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
MIGRATION.md:107
Finding

Documentation recommends persistent plaintext storage and direct printing of AppSecret

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (71)

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The command curls a remote setup script and pipes it directly into sudo bash, allowing network-delivered content to execute immediately as root without inspection. If the upstream endpoint, TLS trust chain, mirror, DNS, or local network is compromised, this becomes arbitrary privileged code execution on the user's machine.

Content

Scanner excerpt · MIGRATION.md (reported line 54)May include surrounding context.

md
cp -r bozo-wechat-publisher ~/.claude/skills/

# 2. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs

# 3. 安装 wenyan-cli

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · MIGRATION.md (reported line 61)May include surrounding context.

e ~/.zshrc

5. 添加 IP 到白名单

curl ifconfig.me

登录 https://mp.weixin.qq.com/ 添加此 IP

text

### Linux

```bash
# 1. 复制 skill 目录
cp -r bozo-wechat-publisher ~/.claude/skills/

# 2. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs

# 3. 安装 wenyan-cli
npm install -g @wenyan-md/cli

# 4. 配置环境变量
echo 'export WECHAT_APP_ID=your_app_id' >> ~/.bashrc
echo 'export WECHAT_APP_SECRET=your_app_secret' >> ~/.bashrc
source ~/.bashrc

# 5. 添加 IP 到白名单
curl ifconfig.me
# 登录 https://mp.weixin.qq.com/ 添加此 IP

Windows

powershell
# 1. 复制 skill 目录
# 复制到 C:\Users\<你的用户名>\.claude\skills\

# 2. 安装 Node.js 18
# 下载: https://nodejs.org/dist/v18.20.2/node-v18.20.2-x64.msi

# 3. 安装 wenyan-cli
npm install -g @wenyan-md/cli

# 4. 配置环境变量
# 系统属性 → 环境变量 → 新建用户变量
# WECHAT_API_ID = your_app_id
# WECHAT_A

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的核心能力是“发布 Markdown 文章到微信公众号草稿箱”。但给出的代码块实际只做本地内容渲染与调试:读取 Markdown 和主题文件,调用 wenyan render 生成 HTML,提取 body 与 CSS,写入本地 HTML 文件,并做可见内容/深色背景检查。代码中没有看到任何与微信公众平台交互的逻辑,例如认证、素材上传、草稿创建、HTTP API 调用或 curl 请求。因此其主要目的与声明明显不一致,属于实质性功能不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

描述与代码的核心目标大体一致:都是将 Markdown 发布到微信公众号草稿箱,且代码确实使用 curl 调用微信 API 完成该任务,也符合“curl 备用方案/兼容所有 Node.js 版本”中的一部分。但该代码块并未体现“支持 wenyan-cli 完整排版”,反而明确提示‘此脚本只做简单格式转换,如需完整排版支持,请使用 wenyan-cli’,说明实际能力弱于声明中的关键功能。此外,代码还会在环境变量缺失时读取 ~/.openclaw/workspace/TOOLS.md 获取 AppID 和 AppSecret,这是一项对本地凭证文件的额外访问行为,声明中未提及。基于功能描述不完整且存在未声明的敏感资源访问,应判定为不准确匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

代码的核心目的与描述大体一致:都是将 Markdown 发布到微信公众号草稿箱,并使用 wenyan-cli 进行排版/发布。但描述声称“支持 wenyan-cli 完整排版和 curl 备用方案,兼容所有 Node.js 版本”,而实际代码只实现了 wenyan-cli 路径,没有任何 curl 备用逻辑,因此存在明显的描述-行为不一致。此外,脚本会访问 $HOME/.openclaw/workspace/TOOLS.md 读取 WECHAT_APP_ID 和 WECHAT_APP_SECRET,并在缺少 wenyan-cli 时自动全局安装 npm 包,这些属于额外的资源访问/执行能力,描述中未体现。综合来看,应判定为存在不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心能力是将 Markdown 文章发布到微信公众号草稿箱,并支持完整排版与备用上传方案;而提供的代码片段只是一个环境初始化脚本,用于从本地 TOOLS.md 文件提取微信公众号凭证并设置环境变量。它没有执行文章读取、Markdown 转换、排版、调用微信公众号接口、上传草稿、也没有使用 wenyan-cli 或 curl。虽然读取凭证可视为发布流程的辅助步骤,但就该代码片段本身而言,其实际主要用途与声明的主要功能明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的核心功能是“将 Markdown 一键发布到微信公众号草稿箱”,并强调支持 wenyan-cli 和 curl 两种发布路径。但实际代码仅是一个 shell 工具:列出内置/自定义主题、展示主题详情、检查 Markdown 文件是否存在,并打印建议使用的 wenyan 命令或主题应用步骤。它没有调用微信公众号接口、没有网络请求、没有 curl、没有执行实际发布命令,甚至对内置主题也只是输出 wenyan publish -f ... -t ... 供用户参考。因此其主要用途与声明的主要用途存在实质性不一致。

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The command chains a network download directly into a privileged shell, which is a classic command-chaining abuse pattern. This removes inspection opportunities and turns any compromise of the remote content path into immediate root code execution.

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

bash
# 1. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs

# 2. 安装 wenyan-cli

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 274)May include surrounding context.

Linux (Ubuntu/Debian)

bash
# 1. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs

# 2. 安装 wenyan-cli
npm install -g @wenyan-md/cli

# 3. 修复 wenyan 命令
mkdir -p ~/.local/bin
cat > ~/.local/bin/wenyan << 'EOF'
#!/bin/bash
node /usr/local/lib/node_modules/@wenyan-md/cli/dist/cli.js "$@"
EOF
chmod +x ~/.local/bin/wenyan
echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc

# 4. 配置环境变量
echo 'export WECHAT_APP_ID=your_app_id' >> ~/.bashrc
echo 'export WECHAT_APP_SECRET=your_app_secret' >> ~/.bashrc

# 5. 应用配置
source ~/.bashrc

Windows

powershell
# 1. 安装 Node.js 18
# 下载: https://nodejs.org/dist/v18.20.2/node-v18.20.2-x64.msi

# 2. 安装 wenyan-cli
npm install -g @wenyan-md/cli

# 3. 创建包装脚本 wenyan.bat
# 保存到 npm 全局目录(运行 npm config get prefix 查看)
@echo off
node "%APPDATA%\npm\node_modules\@wenyan-md\cli\dist\cli.js" %*

# 4. 配置�

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The comment and call pattern indicate parse_frontmatter should use its declared arguments file, output targets, and split frontmatter/content accordingly. But inside the awk block it writes to $3 and $4 even though the shell function only declares and passes two output variables after the file, creating behavior that contradicts the apparent documented intent and making the parser not do what its interface suggests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide tells users to append WECHAT_APP_ID and WECHAT_APP_SECRET directly into shell startup files, which creates long-lived plaintext secrets on disk and makes them automatically available to every future shell session. That increases the risk of accidental disclosure through local compromise, backups, dotfile sync, screen sharing, or support logs, even though this is not an immediate remote exploit by itself.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
89% confidence
Finding

The use of sudo -E specifically preserves the caller's environment while executing a root shell, which can unintentionally pass attacker-controlled or unsafe environment variables into a privileged context. In documentation for a broadly installed skill, this is more dangerous than ordinary sudo because it expands the trust boundary during root execution.

Content

Scanner excerpt · MIGRATION.md (reported line 54)May include surrounding context.

md
cp -r bozo-wechat-publisher ~/.claude/skills/

# 2. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs

# 3. 安装 wenyan-cli

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
89% confidence
Finding

The use of sudo -E specifically preserves the caller's environment while executing a root shell, which can unintentionally pass attacker-controlled or unsafe environment variables into a privileged context. In documentation for a broadly installed skill, this is more dangerous than ordinary sudo because it expands the trust boundary during root execution.

Content

Scanner excerpt · MIGRATION.md (reported line 54)May include surrounding context.

md
cp -r bozo-wechat-publisher ~/.claude/skills/

# 2. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs

# 3. 安装 wenyan-cli

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · MIGRATION.md (reported line 55)May include surrounding context.

md
# 2. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs

# 3. 安装 wenyan-cli
npm install -g @wenyan-md/cli

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Windows instructions tell users to create persistent environment variables for AppID and AppSecret but do not warn that the AppSecret is sensitive or recommend any protection measures. This can lead to unnecessary exposure to other local processes, screenshots, shared profiles, exported environment dumps, or support collection practices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file states that Markdown will be pushed to the WeChat draft box and that local/network images will be automatically uploaded, which are user-data affecting network operations. The description presents these actions as features but does not clearly warn users that article content and images will be transmitted to Tencent/WeChat services and possibly fetched from remote URLs.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 53)May include surrounding context.

md
npm install -g @wenyan-md/cli

# 3. 修复 wenyan 命令(绕过 ESM 模块加载问题)
mkdir -p ~/.local/bin
cat > ~/.local/bin/wenyan << 'EOF'
#!/bin/bash
node /usr/local/lib/node_modules/@wenyan-md/cli/dist/cli.js "$@"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 160)May include surrounding context.

bash
# 创建用户级别的 bin 目录
mkdir -p ~/.local/bin

# 创建 wenyan 包装脚本
cat > ~/.local/bin/wenyan << 'EOF'

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly instructs users to run shell commands (npm, curl, cat, chmod, source) but does not declare any tool scope or permissions. This creates an authorization gap where a user or runtime may not understand that the skill requires command execution and filesystem modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description is broad enough to match generic requests about publishing, uploads, drafts, or articles, which could cause the skill to activate in contexts the user did not intend. In an agent setting, overbroad triggers increase the chance of accidental external publication or credential-dependent actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation does not prominently warn that article text, images, and metadata will be transmitted to external WeChat endpoints using configured credentials. Users may unknowingly upload sensitive content or local images, especially because the skill emphasizes convenience and one-click publishing.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The skill directs users to create a wrapper in ~/.local/bin and modify shell startup files to prepend that directory to PATH, creating persistent execution changes across sessions. Persistence itself is not always malicious, but it is security-relevant because it changes future command resolution and can mask binaries.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

bash
# 创建包装脚本
mkdir -p ~/.local/bin
cat > ~/.local/bin/wenyan << 'EOF'
#!/bin/bash
node /usr/local/lib/node_modules/@wenyan-md/cli/dist/cli.js "$@"

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The migration instructions again create a persistent wrapper and alter PATH, affecting future sessions and potentially overriding another wenyan binary. Repeated persistence guidance raises the chance that users apply it without considering the long-term execution impact.

Content

Scanner excerpt · SKILL.md (reported line 241)May include surrounding context.

md
npm install -g @wenyan-md/cli

# 2. 修复 wenyan 命令
mkdir -p ~/.local/bin
cat > ~/.local/bin/wenyan << 'EOF'
#!/bin/bash
node /usr/local/lib/node_modules/@wenyan-md/cli/dist/cli.js "$@"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

sudo -E preserves the caller's environment while executing as root, which can unintentionally pass attacker-controlled variables into privileged execution. Combined with a piped remote script, this meaningfully increases risk beyond ordinary package installation.

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

bash
# 1. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs

# 2. 安装 wenyan-cli

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

sudo -E preserves the caller's environment while executing as root, which can unintentionally pass attacker-controlled variables into privileged execution. Combined with a piped remote script, this meaningfully increases risk beyond ordinary package installation.

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

bash
# 1. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs

# 2. 安装 wenyan-cli

Static analysis

No suspicious patterns detected.