Back to skill

Security audit

Wechat Blog Write Publish

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent WeChat draft-publishing workflow, but it handles account credentials and a global npm install in ways users should review before using.

Review this skill before installing. Use it only with non-confidential source material you are willing to upload to WeChat, confirm each draft before publishing, avoid putting AppSecret values directly in commands, and prefer a pinned, local, sandboxed install of the CLI instead of the documented global npm install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:82
Finding

Unpinned Third-Party Package Is Installed Globally

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:99
Finding

WeChat AppSecret Is Passed Through Command-Line Arguments

Content
View full analysis
--appsecret ``` The source uses instructional placeholders for the AppID and AppSecret; users are expected to replace them with live credentials. ### Technical Analysis The documented configuration procedure places the WeChat AppSecret directly in a command-line argument. Depending on the operating system, shell, terminal integration, and automation environment, command arguments may be exposed through: - Shell history files - Process inspection utilities while the command is running - CI/CD job output and command tracing - Terminal session recording - Debug, telemetry, or audit logs - Wrapper scripts that record invoked arguments The AppSecret is a sensitive authentication credential. Passing it as an ordinary argument unnecessarily expands the number of locations in which it may persist or become observable. ### Attack Path 1. A user replaces the placeholder with a live WeChat AppSecret and executes the documented command. 2. The shell records the command in history, or another local process observes the process argument list. 3. Alternatively, an automation system logs the expanded command or runs it with command tracing enabled. 4. A local user, malware process, administrator, or log reader obtains the exposed secret. 5. The attacker combines the AppSecret with the corresponding AppID and any required network conditions. 6. The attacker attempts to authenticate to the WeChat API and perform operations allowed to that application credential. ### Impact Assessment Exposure may allow unauthorized use of the associated WeChat application identity within the permissions and platform restrictions assigned to the account. Potential consequences include u ...[truncated 387 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes one-click publication to the WeChat draft box but does not clearly warn that article content, media, and account-linked metadata will be transmitted to an external platform. In an agent skill context, users may assume the action is local or low-risk, so missing disclosure increases the chance of unintended data sharing or accidental publication through a privileged account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to obtain and configure AppID and AppSecret but does not include guidance that these are sensitive credentials that must be protected from logs, screenshots, prompts, shell history, or repository commits. In an agent-assisted workflow, this omission is dangerous because users may paste secrets into insecure contexts or allow the skill to handle them without clear boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to publish generated articles and related assets to a WeChat official account draft box, which necessarily transmits content and possibly images to an external platform. It does not clearly warn users about this outbound data transfer, the sensitivity of referenced source material, or the privacy implications of uploading intermediate content and media.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The README presents the skill entirely in Chinese and frames it around WeChat article creation without stating whether this language requirement is optional or required. Because the policy forbids forcing a specific language or locale without opt-in or justification, the absence of an explicit language choice or documented locale scope is a mild policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description and body of the skill are written as a WeChat public-account article workflow and specify creation of 微信公众号文章, which implies a fixed Chinese-language/platform locale. The file does not mention any user opt-in or alternative language/locale handling, so it may violate language/locale choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.