T08 · Insecure Dependencies
- Location
SKILL.md:82- Finding
Unpinned Third-Party Package Is Installed Globally
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent WeChat draft-publishing workflow, but it handles account credentials and a global npm install in ways users should review before using.
Review this skill before installing. Use it only with non-confidential source material you are willing to upload to WeChat, confirm each draft before publishing, avoid putting AppSecret values directly in commands, and prefer a pinned, local, sandboxed install of the CLI instead of the documented global npm install.
SKILL.md:82Unpinned Third-Party Package Is Installed Globally
SKILL.md:99WeChat AppSecret Is Passed Through Command-Line Arguments
The README promotes one-click publication to the WeChat draft box but does not clearly warn that article content, media, and account-linked metadata will be transmitted to an external platform. In an agent skill context, users may assume the action is local or low-risk, so missing disclosure increases the chance of unintended data sharing or accidental publication through a privileged account.
The README instructs users to obtain and configure AppID and AppSecret but does not include guidance that these are sensitive credentials that must be protected from logs, screenshots, prompts, shell history, or repository commits. In an agent-assisted workflow, this omission is dangerous because users may paste secrets into insecure contexts or allow the skill to handle them without clear boundaries.
The skill instructs the agent to publish generated articles and related assets to a WeChat official account draft box, which necessarily transmits content and possibly images to an external platform. It does not clearly warn users about this outbound data transfer, the sensitivity of referenced source material, or the privacy implications of uploading intermediate content and media.
The README presents the skill entirely in Chinese and frames it around WeChat article creation without stating whether this language requirement is optional or required. Because the policy forbids forcing a specific language or locale without opt-in or justification, the absence of an explicit language choice or documented locale scope is a mild policy issue.
The description and body of the skill are written as a WeChat public-account article workflow and specify creation of 微信公众号文章, which implies a fixed Chinese-language/platform locale. The file does not mention any user opt-in or alternative language/locale handling, so it may violate language/locale choice policy.
No suspicious patterns detected.