Back to skill

Security audit

research-to-wechat

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for WeChat article production, but it gives agents broad authority to upload, update, and sometimes delete WeChat drafts without a clear confirmation boundary.

Review this skill before installing if your WeChat account contains important drafts. Prefer ClawHub installation over the curl-to-bash installer, keep credentials in environment configuration, use dry-run/local rendering until you explicitly want delivery, and require confirmation before any draft update, replacement, or deletion.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (59)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Using '| bash' is a classic chaining pattern that executes untrusted network content in the shell without validation. In the context of an install command shown in a README, this materially increases the chance of arbitrary command execution from a compromised repository, MITM-capable environment, or malicious script update.

Content

Scanner excerpt · README.md (reported line 15)May include surrounding context.

Manual:

bash
curl -fsSL https://raw.githubusercontent.com/Fei2-Labs/skill-genie/main/research-to-wechat/scripts/install-openclaw.sh | bash

Optional runtime integrations:

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the referenced fetch workflow performs undeclared scraping of arbitrary WeChat URLs using a simulated mobile/WeChat User-Agent, that is materially different from the declared research-writing purpose and can conceal bypass-oriented collection of third-party content. Hidden scraping behavior increases legal, privacy, and trust risk because users may unknowingly cause the system to retrieve and archive remote content outside the stated scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the referenced fetch workflow performs undeclared scraping of arbitrary WeChat URLs using a simulated mobile/WeChat User-Agent, that is materially different from the declared research-writing purpose and can conceal bypass-oriented collection of third-party content. Hidden scraping behavior increases legal, privacy, and trust risk because users may unknowingly cause the system to retrieve and archive remote content outside the stated scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the referenced fetch workflow performs undeclared scraping of arbitrary WeChat URLs using a simulated mobile/WeChat User-Agent, that is materially different from the declared research-writing purpose and can conceal bypass-oriented collection of third-party content. Hidden scraping behavior increases legal, privacy, and trust risk because users may unknowingly cause the system to retrieve and archive remote content outside the stated scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the referenced fetch workflow performs undeclared scraping of arbitrary WeChat URLs using a simulated mobile/WeChat User-Agent, that is materially different from the declared research-writing purpose and can conceal bypass-oriented collection of third-party content. Hidden scraping behavior increases legal, privacy, and trust risk because users may unknowingly cause the system to retrieve and archive remote content outside the stated scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the referenced fetch workflow performs undeclared scraping of arbitrary WeChat URLs using a simulated mobile/WeChat User-Agent, that is materially different from the declared research-writing purpose and can conceal bypass-oriented collection of third-party content. Hidden scraping behavior increases legal, privacy, and trust risk because users may unknowingly cause the system to retrieve and archive remote content outside the stated scope.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

md
`draft/update` returning `errcode:0` does **not** mean the content landed. Observed 2026-09-25: the API reported ok while the live draft still held the previous title and body. Never judge success from the write response, and never report success to the user from it.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The draft replacement rule explicitly instructs deletion of an old draft before re-creating it, yet provides no safety prompt, backup requirement, or confirmation for this destructive operation. This creates a clear risk of irreversible content loss or accidental deletion in a live WeChat workspace.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
80% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/_wechat_design_catalog.py (reported line 133)May include surrounding context.

python
def choose_text(texts: list[dict[str, object]], include: tuple[str, ...], exclude: tuple[str, ...], size: int) -> dict[str, object]:
    for node in texts:
        name = str(node.get("name", "")).lower()
        if any(token in name for token in include) and not any(token in name for token in exclude):
            return node
    ranked = sorted(texts, key=lambda item: abs(int(item.get("fontSize", size) or size) - size))
    return ranked[0] if ranked else {}

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
80% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/_wechat_design_catalog.py (reported line 141)May include surrounding context.

python
def choose_text(texts: list[dict[str, object]], include: tuple[str, ...], exclude: tuple[str, ...], size: int) -> dict[str, object]:
    for node in texts:
        name = str(node.get("name", "")).lower()
        if any(token in name for token in include) and not any(token in name for token in exclude):
            return node
    ranked = sorted(texts, key=lambda item: abs(int(item.get("fontSize", size) or size) - size))
    return ranked[0] if ranked else {}

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
80% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/_wechat_design_catalog.py (reported line 147)May include surrounding context.

python
def choose_text(texts: list[dict[str, object]], include: tuple[str, ...], exclude: tuple[str, ...], size: int) -> dict[str, object]:
    for node in texts:
        name = str(node.get("name", "")).lower()
        if any(token in name for token in include) and not any(token in name for token in exclude):
            return node
    ranked = sorted(texts, key=lambda item: abs(int(item.get("fontSize", size) or size) - size))
    return ranked[0] if ranked else {}

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash pattern is a classic high-risk execution chain because it removes the inspection boundary between download and execution. In this skill context, the installer also fetches and installs additional repository contents, so a compromised upstream source could directly plant malicious files into the OpenClaw skills directory and potentially influence later agent behavior.

Content

Scanner excerpt · scripts/install-openclaw.sh (reported line 9)May include surrounding context.

sh
# For ClawHub users: clawhub install research-to-wechat
#
# Usage:
#   curl -fsSL https://raw.githubusercontent.com/Fei2-Labs/skill-genie/main/research-to-wechat/scripts/install-openclaw.sh | bash
#

set -e

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/jev_rewrite.py (reported line 928)May include surrounding context.

python
parser = build_parser()
    args = parser.parse_args(list(argv) if argv is not None else None)
    out = stdout if stdout is not None else sys.stdout
    environment = env if env is not None else dict(os.environ)

    if args.policy:
        emit(out, policy())

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CHANGELOG.md (reported line 9)May include surrounding context.

md
### Added

- `references/original-rewrite.md` — canonical contract for the optional `rewriteMode: methodology-only`: activation (readable source material AND explicit rewrite intent, both required), the intake evidence record, positive/negative trigger examples, private source separation, methodology brief and exclusion ledger, the independent research ledger, persona resolution, the five Jev evaluation dimensions, gate policy `screening-policy-1`, round records, `rewrite-report.md`, and version binding after render normalization
- `scripts/jev_rewrite.py` — standard-library-only screening evaluator with offline `--help`, `--policy`, `--example-input`, `--example-output`; credential comes from `TYPESAFE_API_KEY` in the environment
- `tests/` — offline unit and documentation/regression tests; no network call and no WeChat write

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L071 says every article must end with "## 参考链接" or "## References". This imposes specific language/locale output forms in natural language, but the file does not explain that the skill is region-specific or that the user may choose the output language, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README describes creating local workspace files, uploading images, and saving WeChat drafts, but it does not clearly warn users that local files will be written and article content may be transmitted to third-party WeChat services. In a skill that processes potentially sensitive notes, drafts, transcripts, or source material, missing consent and data-flow disclosure can lead to unintended disclosure or modification of user data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example requests and dedicated Chinese section strongly frame the skill around Chinese/WeChat usage, but the README does not explicitly state that the skill is China/WeChat-specific or offer the user a language choice. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares extensive capabilities to read/write files, access environment variables, invoke shell commands, and make network/API requests, but it does not declare an explicit tool scope or permission boundary. That creates an authorization and transparency gap: users may invoke a seemingly content-focused skill without understanding it can exfiltrate data, modify local files, or interact with external services such as WeChat APIs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation description is broad enough to match ordinary research, writing, rewriting, formatting, and publishing requests, which can cause over-triggering of a high-capability skill. Because this skill can later reach shell, files, env secrets, and external APIs, ambiguous activation increases the chance of unintended data handling or network actions in contexts where the user only wanted basic writing help.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description does not upfront warn users that the workflow may save drafts to WeChat and perform networked delivery operations. That omission is dangerous because it can lead users to provide sensitive notes, drafts, or source material without realizing the skill may transmit them to third-party services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The skill includes explicit code to send requests to the WeChat draft API, which is an external transmission of article content and metadata. In a publishing skill this behavior is expected, but it is still security-relevant because sensitive drafts, titles, digests, and potentially embedded data leave the local environment and may be transmitted using locally stored access tokens.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

md
import json,urllib.request,sys
   token=open('/tmp/wx_token.txt').read().strip()
   media_id=sys.argv[1]
   req=urllib.request.Request('https://api.weixin.qq.com/cgi-bin/draft/get?access_token='+token,
     data=json.dumps({'media_id':media_id}).encode(),headers={'Content-Type':'application/json'})
   a=json.load(urllib.request.urlopen(req,timeout=30))['news_item'][0]
   print('TITLE:',a['title']); print('LEN:',len(a['content']))

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a pipeline that turns source materials into researched, sourced articles, WeChat-ready HTML, draft assets, and optional distribution. This file is instead a static Penpot-style design document containing hard-coded article mockups, CTA cards, and layout presets, with no code or workflow logic implementing research, evidence ledgers, Markdown/HTML conversion, draft generation, or distribution behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This .pen design file hard-codes nearly all user-facing text in Chinese across multiple layouts, including CTA instructions and article content. Because the file does not indicate that the content is region-specific or offer any language/locale opt-in, it can violate a policy requiring language choice or documented locale constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example explicitly instructs saving generated content to a WeChat draft box, which implies transmission of article text, images, metadata, and possibly user-provided source material to an external platform. In a research-to-publishing skill, omitting any privacy or external-transmission notice can cause users to unknowingly send sensitive or unpublished material off-platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Referencing WECHAT_APPID/WECHAT_SECRET and direct use of the official draft API without credential-handling guidance creates a real risk of unsafe secret use and unintended external submission. Users may assume credentials can be freely supplied in prompts or that draft delivery is purely local, increasing the chance of secret exposure and unauthorized publishing actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.