Back to skill

Security audit

"微信公众号草稿上传"

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a WeChat draft-upload purpose, but it also ships under-disclosed draft-reading/export scripts and exposes WeChat credentials in source and command-line usage.

Review before installing. Remove the hardcoded credential wrapper and the get_draft scripts unless you explicitly need draft export, rotate any exposed AppSecret, avoid passing secrets on the command line, and run only with a WeChat account and workspace where local plaintext draft exports would be acceptable.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run_upload.py:3
Finding

Hardcoded WeChat Application Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:45
Finding

AppSecret Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/get_draft.py:30
Finding

Undeclared Over-Fetching and Plaintext Storage of Private Draft Content

Content
View full analysis
{article.get('content')} """) ``` The indexed variant uses the same batch request even though it only needs one selected draft. ### Technical Analysis The declared Skill functionality is uploading a local Markdown article to the WeChat draft box. Retrieving existing unpublished drafts is not required for that workflow. The scripts set `no_content` to `0`, causing the API to return complete draft bodies for up to 20 entries. This exceeds the minimum data required to list drafts or locate a target. Printing the body can disclose it through terminal capture and automation logs. Writing it to a predictable file in the current directory creates an additional plaintext copy wi ...[truncated 1139 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run_upload.py:14
Finding

Relative Script Execution Enables Local Code Substitution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:34
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that claims to create drafts but instead only queries existing drafts and saves their contents locally represents a significant trust violation. In this context, the user is expected to supply sensitive WeChat credentials for publishing, so undeclared access to historical drafts or local export of article contents could leak proprietary or unpublished material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill that claims to create drafts but instead only queries existing drafts and saves their contents locally represents a significant trust violation. In this context, the user is expected to supply sensitive WeChat credentials for publishing, so undeclared access to historical drafts or local export of article contents could leak proprietary or unpublished material.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/wechat_api.md (reported line 14)May include surrounding context.

核心接口

1. 获取 Access Token

text
GET https://api.weixin.qq.com/cgi-bin/token
    ?grant_type=client_credential

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script’s stated purpose in the skill metadata is uploading local Markdown into the WeChat draft box, but this file instead retrieves existing drafts and can export their full HTML content. That scope mismatch is dangerous because a user invoking an upload-oriented skill may unknowingly grant credentials that are then used for data discovery and exfiltration of existing private draft content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script's behavior materially differs from the declared skill purpose: instead of uploading local Markdown to create a draft, it fetches existing drafts from the WeChat account and prints/exports their HTML content. In a skill context, this expands access from publishing to content exfiltration, increasing the risk of unauthorized retrieval of unpublished articles and account data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file hardcodes a WeChat appid and secret directly into sys.argv, exposing live credentials in source code. In a skill designed to publish content to a public account, compromised credentials could enable unauthorized draft creation, content manipulation, API abuse, and possible takeover of connected publishing workflows.

Content

No source excerpt is available for this finding.

exec() call detected

High
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

The script executes the full contents of a local file with exec(), which means any modification to upload_draft.py results in arbitrary code execution in the current process. In an agent skill context, this is especially dangerous because the wrapper auto-runs with embedded credentials and a target file path, so tampering with the referenced script can immediately lead to credential theft, unauthorized API use, or broader system compromise.

Content

Scanner excerpt · scripts/run_upload.py (reported line 14)May include surrounding context.

python
sys.stdout = io.TextIOWrapper(sys.stdout.buffer, encoding='utf-8')
sys.stderr = io.TextIOWrapper(sys.stderr.buffer, encoding='utf-8')

exec(open('upload_draft.py', encoding='utf-8').read())

Direct flow: open (file read) → exec (code execution)

High
Category
Data Flow
Confidence
98% confidence
Finding

This is a true arbitrary-code-execution pattern: file contents are read directly from disk and passed into exec() without validation. If an attacker, another tool, or even an accidental local change alters upload_draft.py, the wrapper will execute that code with the same privileges and access to the embedded WeChat credentials.

Content

Scanner excerpt · scripts/run_upload.py (reported line 14)May include surrounding context.

python
sys.stdout = io.TextIOWrapper(sys.stdout.buffer, encoding='utf-8')
sys.stderr = io.TextIOWrapper(sys.stderr.buffer, encoding='utf-8')

exec(open('upload_draft.py', encoding='utf-8').read())

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/upload_draft.py (reported line 63)May include surrounding context.

python
# ─────────────────────────────────────────────
# 2. 获取 Access Token
# ─────────────────────────────────────────────

def get_access_token(appid, secret):

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill requests users to provide local file paths, runs a Python script, and calls external WeChat APIs, but the manifest declares no explicit tool scope or permissions boundary. This creates an authorization gap where file read/write and network actions may occur without clear least-privilege constraints or user-visible guardrails.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger description is broad and ambiguous, covering general requests like publishing or uploading to a public account without tight boundaries on prerequisites, account scope, or side effects. Overbroad activation increases the chance the agent invokes a credentialed, networked, file-accessing skill in situations where the user did not intend to authorize those actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Accepting the AppSecret as a command-line argument exposes it to process listings, shell history, audit logs, and job runners. In this script, the credential is highly sensitive because it enables access token acquisition and subsequent access to WeChat draft data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code enumerates all draft titles and, when a title is provided, prints the full draft HTML and metadata to stdout. In the context of an upload-focused skill, this expands capabilities into reading and disclosing existing content, increasing the chance of unintended exposure through logs, terminal history, or downstream agent handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script saves retrieved draft HTML content to a local file automatically, creating persistent copies of potentially sensitive unpublished articles without an explicit warning or consent step. This increases the risk of local data leakage through shared workstations, backups, source trees, or accidental reuse of the exported file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script sends the AppID and AppSecret to the WeChat token endpoint, and later uses the resulting access token in another API request. Although the code prints success/failure messages, it does not clearly warn users that their supplied credentials and account draft data will be transmitted to an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/wechat_api.md (reported line 16)May include surrounding context.

md
def get_access_token(appid, secret):
    """获取 access_token"""
    url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}"
    response = requests.get(url)
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/wechat_api.md (reported line 26)May include surrounding context.

md
def get_access_token(appid, secret):
    """获取 access_token"""
    url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}"
    response = requests.get(url)
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/wechat_api.md (reported line 38)May include surrounding context.

md
def get_access_token(appid, secret):
    """获取 access_token"""
    url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}"
    response = requests.get(url)
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get_draft.py (reported line 17)May include surrounding context.

python
def get_access_token(appid, secret):
    """获取 access_token"""
    url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}"
    response = requests.get(url)
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get_draft.py (reported line 32)May include surrounding context.

python
def get_access_token(appid, secret):
    """获取 access_token"""
    url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}"
    response = requests.get(url)
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get_draft_by_index.py (reported line 17)May include surrounding context.

python
def get_access_token(appid, secret):
    """获取 access_token"""
    url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}"
    response = requests.get(url)
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get_draft_by_index.py (reported line 32)May include surrounding context.

python
def get_access_token(appid, secret):
    """获取 access_token"""
    url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}"
    response = requests.get(url)
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/upload_draft.py (reported line 68)May include surrounding context.

python
def get_access_token(appid, secret):
    """获取 access_token"""
    url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}"
    response = requests.get(url)
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/upload_draft.py (reported line 243)May include surrounding context.

python
def get_access_token(appid, secret):
    """获取 access_token"""
    url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}"
    response = requests.get(url)
    result = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/upload_draft.py (reported line 260)May include surrounding context.

python
def get_access_token(appid, secret):
    """获取 access_token"""
    url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}"
    response = requests.get(url)
    result = response.json()

Static analysis

No suspicious patterns detected.