T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:261- Finding
Privileged execution of a mutable remote installation script
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly a real WeChat draft publisher, but it uses unsafe installation and credential/file-upload patterns that users should review before installing.
Install only if you are comfortable granting this skill access to your WeChat official account credentials and sending article content and images to WeChat. Avoid the curl-to-sudo-bash setup, do not store AppSecret in shell startup files, review any Markdown cover paths before publishing, and prefer a pinned, manually installed wenyan-cli with credentials supplied only for the specific publishing command.
SKILL.md:261Privileged execution of a mutable remote installation script
scripts/publish-card-theme-v2.sh:42Automatic installation of an unpinned global npm dependency
scripts/publish-card-theme-v2.sh:177Unrestricted cover path can upload arbitrary readable local files
scripts/publish-card-theme-v2.sh:48Implicit credential extraction from the Agent workspace
scripts/publish-curl.sh:85WeChat AppSecret is placed in URL query strings
scripts/publish-curl.sh:259Unsafe JSON construction from attacker-influenced Markdown fields
MIGRATION.md:107Documentation recommends persistent plaintext storage and direct printing of AppSecret
The command curls a remote setup script and pipes it directly into sudo bash, allowing network-delivered content to execute immediately as root without inspection. If the upstream endpoint, TLS trust chain, mirror, DNS, or local network is compromised, this becomes arbitrary privileged code execution on the user's machine.
cp -r bozo-wechat-publisher ~/.claude/skills/
# 2. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs
# 3. 安装 wenyan-cli
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
e ~/.zshrc
curl ifconfig.me
### Linux
```bash
# 1. 复制 skill 目录
cp -r bozo-wechat-publisher ~/.claude/skills/
# 2. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs
# 3. 安装 wenyan-cli
npm install -g @wenyan-md/cli
# 4. 配置环境变量
echo 'export WECHAT_APP_ID=your_app_id' >> ~/.bashrc
echo 'export WECHAT_APP_SECRET=your_app_secret' >> ~/.bashrc
source ~/.bashrc
# 5. 添加 IP 到白名单
curl ifconfig.me
# 登录 https://mp.weixin.qq.com/ 添加此 IP
# 1. 复制 skill 目录
# 复制到 C:\Users\<你的用户名>\.claude\skills\
# 2. 安装 Node.js 18
# 下载: https://nodejs.org/dist/v18.20.2/node-v18.20.2-x64.msi
# 3. 安装 wenyan-cli
npm install -g @wenyan-md/cli
# 4. 配置环境变量
# 系统属性 → 环境变量 → 新建用户变量
# WECHAT_API_ID = your_app_id
# WECHAT_A
声明描述的核心能力是“发布 Markdown 文章到微信公众号草稿箱”。但给出的代码块实际只做本地内容渲染与调试:读取 Markdown 和主题文件,调用 wenyan render 生成 HTML,提取 body 与 CSS,写入本地 HTML 文件,并做可见内容/深色背景检查。代码中没有看到任何与微信公众平台交互的逻辑,例如认证、素材上传、草稿创建、HTTP API 调用或 curl 请求。因此其主要目的与声明明显不一致,属于实质性功能不匹配。
描述与代码的核心目标大体一致:都是将 Markdown 发布到微信公众号草稿箱,且代码确实使用 curl 调用微信 API 完成该任务,也符合“curl 备用方案/兼容所有 Node.js 版本”中的一部分。但该代码块并未体现“支持 wenyan-cli 完整排版”,反而明确提示‘此脚本只做简单格式转换,如需完整排版支持,请使用 wenyan-cli’,说明实际能力弱于声明中的关键功能。此外,代码还会在环境变量缺失时读取 ~/.openclaw/workspace/TOOLS.md 获取 AppID 和 AppSecret,这是一项对本地凭证文件的额外访问行为,声明中未提及。基于功能描述不完整且存在未声明的敏感资源访问,应判定为不准确匹配。
代码的核心目的与描述大体一致:都是将 Markdown 发布到微信公众号草稿箱,并使用 wenyan-cli 进行排版/发布。但描述声称“支持 wenyan-cli 完整排版和 curl 备用方案,兼容所有 Node.js 版本”,而实际代码只实现了 wenyan-cli 路径,没有任何 curl 备用逻辑,因此存在明显的描述-行为不一致。此外,脚本会访问 $HOME/.openclaw/workspace/TOOLS.md 读取 WECHAT_APP_ID 和 WECHAT_APP_SECRET,并在缺少 wenyan-cli 时自动全局安装 npm 包,这些属于额外的资源访问/执行能力,描述中未体现。综合来看,应判定为存在不匹配。
声明描述的核心能力是将 Markdown 文章发布到微信公众号草稿箱,并支持完整排版与备用上传方案;而提供的代码片段只是一个环境初始化脚本,用于从本地 TOOLS.md 文件提取微信公众号凭证并设置环境变量。它没有执行文章读取、Markdown 转换、排版、调用微信公众号接口、上传草稿、也没有使用 wenyan-cli 或 curl。虽然读取凭证可视为发布流程的辅助步骤,但就该代码片段本身而言,其实际主要用途与声明的主要功能明显不一致,因此应判定为描述与行为不匹配。
声明描述的核心功能是“将 Markdown 一键发布到微信公众号草稿箱”,并强调支持 wenyan-cli 和 curl 两种发布路径。但实际代码仅是一个 shell 工具:列出内置/自定义主题、展示主题详情、检查 Markdown 文件是否存在,并打印建议使用的 wenyan 命令或主题应用步骤。它没有调用微信公众号接口、没有网络请求、没有 curl、没有执行实际发布命令,甚至对内置主题也只是输出 wenyan publish -f ... -t ... 供用户参考。因此其主要用途与声明的主要用途存在实质性不一致。
The command chains a network download directly into a privileged shell, which is a classic command-chaining abuse pattern. This removes inspection opportunities and turns any compromise of the remote content path into immediate root code execution.
# 1. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs
# 2. 安装 wenyan-cli
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
Linux (Ubuntu/Debian)
# 1. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs
# 2. 安装 wenyan-cli
npm install -g @wenyan-md/cli
# 3. 修复 wenyan 命令
mkdir -p ~/.local/bin
cat > ~/.local/bin/wenyan << 'EOF'
#!/bin/bash
node /usr/local/lib/node_modules/@wenyan-md/cli/dist/cli.js "$@"
EOF
chmod +x ~/.local/bin/wenyan
echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc
# 4. 配置环境变量
echo 'export WECHAT_APP_ID=your_app_id' >> ~/.bashrc
echo 'export WECHAT_APP_SECRET=your_app_secret' >> ~/.bashrc
# 5. 应用配置
source ~/.bashrc
# 1. 安装 Node.js 18
# 下载: https://nodejs.org/dist/v18.20.2/node-v18.20.2-x64.msi
# 2. 安装 wenyan-cli
npm install -g @wenyan-md/cli
# 3. 创建包装脚本 wenyan.bat
# 保存到 npm 全局目录(运行 npm config get prefix 查看)
@echo off
node "%APPDATA%\npm\node_modules\@wenyan-md\cli\dist\cli.js" %*
# 4. 配置�
The comment and call pattern indicate parse_frontmatter should use its declared arguments file, output targets, and split frontmatter/content accordingly. But inside the awk block it writes to $3 and $4 even though the shell function only declares and passes two output variables after the file, creating behavior that contradicts the apparent documented intent and making the parser not do what its interface suggests.
The guide tells users to append WECHAT_APP_ID and WECHAT_APP_SECRET directly into shell startup files, which creates long-lived plaintext secrets on disk and makes them automatically available to every future shell session. That increases the risk of accidental disclosure through local compromise, backups, dotfile sync, screen sharing, or support logs, even though this is not an immediate remote exploit by itself.
The use of sudo -E specifically preserves the caller's environment while executing a root shell, which can unintentionally pass attacker-controlled or unsafe environment variables into a privileged context. In documentation for a broadly installed skill, this is more dangerous than ordinary sudo because it expands the trust boundary during root execution.
cp -r bozo-wechat-publisher ~/.claude/skills/
# 2. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs
# 3. 安装 wenyan-cli
The use of sudo -E specifically preserves the caller's environment while executing a root shell, which can unintentionally pass attacker-controlled or unsafe environment variables into a privileged context. In documentation for a broadly installed skill, this is more dangerous than ordinary sudo because it expands the trust boundary during root execution.
cp -r bozo-wechat-publisher ~/.claude/skills/
# 2. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs
# 3. 安装 wenyan-cli
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# 2. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs
# 3. 安装 wenyan-cli
npm install -g @wenyan-md/cli
The Windows instructions tell users to create persistent environment variables for AppID and AppSecret but do not warn that the AppSecret is sensitive or recommend any protection measures. This can lead to unnecessary exposure to other local processes, screenshots, shared profiles, exported environment dumps, or support collection practices.
This markdown file states that Markdown will be pushed to the WeChat draft box and that local/network images will be automatically uploaded, which are user-data affecting network operations. The description presents these actions as features but does not clearly warn users that article content and images will be transmitted to Tencent/WeChat services and possibly fetched from remote URLs.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
npm install -g @wenyan-md/cli
# 3. 修复 wenyan 命令(绕过 ESM 模块加载问题)
mkdir -p ~/.local/bin
cat > ~/.local/bin/wenyan << 'EOF'
#!/bin/bash
node /usr/local/lib/node_modules/@wenyan-md/cli/dist/cli.js "$@"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 创建用户级别的 bin 目录
mkdir -p ~/.local/bin
# 创建 wenyan 包装脚本
cat > ~/.local/bin/wenyan << 'EOF'
The skill clearly instructs users to run shell commands (npm, curl, cat, chmod, source) but does not declare any tool scope or permissions. This creates an authorization gap where a user or runtime may not understand that the skill requires command execution and filesystem modification.
The trigger description is broad enough to match generic requests about publishing, uploads, drafts, or articles, which could cause the skill to activate in contexts the user did not intend. In an agent setting, overbroad triggers increase the chance of accidental external publication or credential-dependent actions.
The documentation does not prominently warn that article text, images, and metadata will be transmitted to external WeChat endpoints using configured credentials. Users may unknowingly upload sensitive content or local images, especially because the skill emphasizes convenience and one-click publishing.
The skill directs users to create a wrapper in ~/.local/bin and modify shell startup files to prepend that directory to PATH, creating persistent execution changes across sessions. Persistence itself is not always malicious, but it is security-relevant because it changes future command resolution and can mask binaries.
# 创建包装脚本
mkdir -p ~/.local/bin
cat > ~/.local/bin/wenyan << 'EOF'
#!/bin/bash
node /usr/local/lib/node_modules/@wenyan-md/cli/dist/cli.js "$@"
The migration instructions again create a persistent wrapper and alter PATH, affecting future sessions and potentially overriding another wenyan binary. Repeated persistence guidance raises the chance that users apply it without considering the long-term execution impact.
npm install -g @wenyan-md/cli
# 2. 修复 wenyan 命令
mkdir -p ~/.local/bin
cat > ~/.local/bin/wenyan << 'EOF'
#!/bin/bash
node /usr/local/lib/node_modules/@wenyan-md/cli/dist/cli.js "$@"
sudo -E preserves the caller's environment while executing as root, which can unintentionally pass attacker-controlled variables into privileged execution. Combined with a piped remote script, this meaningfully increases risk beyond ordinary package installation.
# 1. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs
# 2. 安装 wenyan-cli
sudo -E preserves the caller's environment while executing as root, which can unintentionally pass attacker-controlled variables into privileged execution. Combined with a piped remote script, this meaningfully increases risk beyond ordinary package installation.
# 1. 安装 Node.js 18
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt-get install -y nodejs
# 2. 安装 wenyan-cli
No suspicious patterns detected.