Back to skill

Security audit

Wechat Mini App

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly provides WeChat mini app scaffolding snippets, but it also includes an unrelated command script that silently saves user-provided text to a local history file.

Review this package before installing because one included script does more than mini app development: it can retain text you pass to writing, translation, polishing, and similar commands in a local history file. Treat the generated mini app code as illustrative only, especially for authentication, storage, payment, location, and network examples.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:35
Finding

Undisclosed Plaintext Persistence of User-Provided Content

Content
View full analysis
> "$DATA_DIR/history.log"; } ``` The destination is initialized as follows: ```bash DATA_DIR="${WECHAT_MINI_APP_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/wechat-mini-app}" DB="$DATA_DIR/data.log" mkdir -p "$DATA_DIR" ``` The `_log` function is called by commands that process user-provided content, including `write`, `title`, `outline`, `polish`, `hashtag`, `platform`, `hot`, `template`, `translate`, and `proofread`. ### Technical Analysis The script silently appends command names and user-provided arguments to the persistent file `$DATA_DIR/history.log`. The project documentation does not disclose this behavior, offer an opt-in mechanism, or provide retention and deletion controls. The script also relies on the process umask instead of explicitly applying restrictive permissions to the data directory and history file. Under a permissive umask or unusual preexisting directory configuration, other local users or processes could read the stored content. Inputs supplied to writing, translation, polishing, or proofreading commands may contain confidential drafts, business information, personal data, or other sensitive material. Persisting raw input in plaintext creates unnecessary local data exposure. This does not grant elevated privileges and does not transmit data to a remote service. The affected scope is the confidentiality and retention of content supplied by users who execute the script. ### Attack Path 1. A user invokes a supported command and supplies potentially sensitive content as an argument. 2. The selected command passes part of that content to `_log`. 3. `_log` appends the command name and co ...[truncated 937 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description and trigger text are broad and generic, covering general 'wechat mini app capabilities' and development tasks without meaningful scoping. This can cause the skill to activate on underspecified requests and steer users into code generation, configuration, or deployment flows they did not explicitly intend, increasing the chance of unsafe or irrelevant actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly advertises configuration, deployment, publishing, terminal use, and automation pipelines, yet provides no warning or safety gating for potentially impactful operations. In practice, this can normalize requests that alter project state or support release workflows without prompting the user to verify environment, target, credentials, or consequences.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/miniapp.sh (reported line 146)May include surrounding context.

sh
apis = {
        "request": """// HTTP Request
wx.request({
  url: 'https://api.example.com/data',
  method: 'GET',
  header: { 'Authorization': 'Bearer ' + token },
  success(res) { console.log(res.data); },

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/miniapp.sh (reported line 158)May include surrounding context.

sh
apis = {
        "request": """// HTTP Request
wx.request({
  url: 'https://api.example.com/data',
  method: 'GET',
  header: { 'Authorization': 'Bearer ' + token },
  success(res) { console.log(res.data); },

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The generated login snippet stores an authentication token locally with wx.setStorageSync('token', result.data.token) without any discussion of token scope, lifetime, device-sharing risk, logout handling, or user disclosure. In a scaffold-generating skill, insecure defaults are likely to be copied into production apps, which can increase the risk of token misuse or unintended persistence on compromised/shared devices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The location snippet retrieves precise device location and logs coordinates without showing any surrounding consent UX, purpose explanation, denial handling, or data-minimization guidance. Although WeChat may enforce platform permissions, this example normalizes collecting sensitive location data without privacy context, which is risky when copied into real applications.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The review checklist asserts compliance-oriented handling of user data at L242-L245, but the tool also generates code snippets that store authentication tokens in local storage (L157-L163) and demonstrates clearing all local storage wholesale (L188-L196). This is not just incomplete documentation: the checklist presents data handling as a reviewed compliance item while the provided implementation examples encourage sensitive-state handling patterns without any privacy, retention, or scoping guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Natural-language strings in the description and command outputs consistently constrain the tool to Chinese content generation and Chinese-language workflows. This enforces a specific language/locale without documenting user choice or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script logs user-supplied content to a local history file via _log without clearly disclosing this behavior in help text or command output. Because the tool handles free-form writing prompts and translated text, users may enter sensitive personal or proprietary content that is then persistently stored on disk, creating a privacy and data exposure risk for other local users, backups, or incidentally shared files.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The FAQ states the tool is suitable for '任何需要wechat mini app helper的人' ('anyone who needs wechat mini app helper'), which is circular and provides no concrete trigger scope. Without specific conditions, this broad phrasing increases ambiguity about when the skill should be invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.