Back to skill

Security audit

wechat-article-search-api-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent BrowserAct-powered WeChat article search tool, but it asks users to provide an API key through the agent conversation and sends search inputs to a third-party API without enough user-facing scoping.

Review before installing. Use this only for non-sensitive WeChat research unless you are comfortable sending the search terms and date filters to BrowserAct. Do not paste your BrowserAct API key into chat; configure it through a protected environment variable or secret manager, and rotate it if it was previously shared in a conversation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:28
Finding

API Key Solicitation Through Agent Conversation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:28-31; scripts/wechat_article_search_api.py:86-90
Vulnerability Type: Sensitive credential exposure through insecure operational guidance
Risk Level: Medium

Vulnerable Code and Instructions

SKILL.md:28-31:

markdown
## 🔑 API Key Guidance Flow
Before running, check the `BROWSERACT_API_KEY` environment variable. If not set, do not take other actions; request and wait for the user to provide it.
**The Agent must inform the user**:
> "Since you have not configured the BrowserAct API Key, please go to the [BrowserAct Console](https://www.browseract.com/reception/integrations) to get your Key."

scripts/wechat_article_search_api.py:86-90:

python
if not api_key:
    print("\n[!] ERROR: BrowserAct API Key is missing.", flush=True)
    print("Please follow these steps:", flush=True)
    print("1. Go to: https://www.browseract.com/reception/integrations", flush=True)
    print("2. Copy your API Key.", flush=True)
    print("3. Provide it to me or set it as an environment variable (BROWSERACT_API_KEY).", flush=True)

Technical Analysis

The Skill explicitly instructs the Agent to request and wait for the user's BrowserAct API key, while the script tells the user to “Provide it to me.” This encourages users to disclose a bearer credential through the Agent conversation.

API keys are sensitive authentication material. Secrets entered into an Agent conversation may be retained in conversation history, execution traces, application logs, monitoring systems, or model-provider telemetry. Anyone with access to those records could potentially recover and reuse the credential.

Conversational disclosure is not required for the declared functionality. The script already reads BROWSERACT_API_KEY from the local environment:

python
api_key = os.getenv("BROWSERACT_API_KEY")

Consequently, requesting the secret through the Agent ...[truncated 1931 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all instructions asking users to provide or paste an API key into the Agent conversation.

  2. Replace the guidance in SKILL.md with instructions to configure the secret locally through BROWSERACT_API_KEY.

  3. Change the script message to language such as:

    python
    print(
        "Set BROWSERACT_API_KEY securely in the execution environment. "
        "Do not paste API keys into chat or command-line arguments.",
        flush=True,
    )
    
  4. Use the hosting platform's secret manager or protected environment-variable injection mechanism where available.

  5. Do not accept the API key as a command-line argument because command lines may be exposed through process listings, shell history, and execution logs.

  6. Ensure application logs and error reports never print the Authorization header or environment-variable value.

  7. Apply least privilege to BrowserAct keys, including account scoping, quota restrictions, expiration, and rotation where supported.

  8. Advise users who previously disclosed a key through a conversation to revoke or rotate it and review associated API activity for unauthorized use.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a broad WeChat article extraction skill that can retrieve full article bodies, metadata, and support multiple monitoring/research use cases. The actual code only invokes a fixed BrowserAct workflow template with three inputs: keywords, limit (named Date_limit), and publication_date. It polls until completion and returns the workflow output verbatim. There is no code-level handling of WeChat links, no parsing of article body, no extraction of author or publication date beyond passing a date filter into the remote workflow, and no persistent monitoring logic. While the remote BrowserAct template may possibly do more, the supplied code chunk only demonstrates a keyword/date task launcher and result fetcher. That is materially narrower than the declared purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares environment and network capabilities via metadata but does not define an explicit tool scope such as permissions or allowed-tools. That weakens least-privilege boundaries and can let an agent invoke external networked behavior and access secrets without clear user-visible constraints, which is risky for a skill that sends user queries to a third-party API.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages very broad proactive invocation across many common research and monitoring requests, which can cause an agent to send user prompts or topics to an external service without sufficiently explicit user intent. In context, this is more dangerous because the skill performs third-party network actions and may process sensitive research, brand, PR, or competitor-monitoring queries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill lacks a user-facing disclosure that search keywords and related parameters will be transmitted to a third-party API. This creates a privacy and data-handling risk because users may provide sensitive company research terms, names, or monitoring topics without realizing the data leaves the local agent environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/wechat_article_search_api.py (reported line 15)May include surrounding context.

python
# API Configuration
TEMPLATE_ID = "84396171023358338"
API_BASE_URL = "https://api.browseract.com/v2/workflow"

def run_wechat_article_search_task(api_key, keywords, limit=10, publication_date="3月11日"):
    headers = {"Authorization": f"Bearer {api_key}"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The script sends user-supplied keywords, publication date, and the Bearer API token to a third-party BrowserAct service, which is an external data transmission boundary. In the context of an agent skill that may process sensitive research, monitoring, or brand-tracking queries, this can expose confidential inputs and operational metadata to an external provider without any validation, minimization, timeout controls, or explicit consent flow.

Content

Scanner excerpt · scripts/wechat_article_search_api.py (reported line 31)May include surrounding context.

python
# 1. Start Task
    print(f"Start Task", flush=True)
    try:
        res = requests.post(f"{API_BASE_URL}/run-task-by-template", json=payload, headers=headers).json()
    except Exception as e:
        print(f"Error: Connection to API failed - {e}", flush=True)
        return None

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code explicitly overrides stdout and stderr to UTF-8, which imposes a specific output encoding regardless of the user's environment or locale preferences. This is a natural-language policy concern because it forces a locale-related behavior without offering user choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.