Back to skill

Security audit

Official Account Assistant

Security checks across malware telemetry and agentic risk

Overview

This skill is a plausible publishing assistant, but it requests powerful public-account publishing actions without clear safeguards and promotes hiding AI authorship.

Review before installing. Use this only for drafting or editing unless the publisher adds clear permission scopes and mandatory preview/confirmation before upload, scheduling, publishing, or mass sending. Do not authorize a real WeChat official account or run any referenced helper scripts unless you can inspect them first. Avoid using the AI-humanizing feature to fabricate personal experience or conceal AI assistance where disclosure is expected.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill advertises operational capabilities that imply local file access and article asset handling, but it declares no permissions. That creates a transparency and consent gap: users and hosting platforms cannot accurately assess what data the skill may read or write before execution. In a skill that rewrites content, manages drafts, and handles publishing assets, undeclared file access increases the risk of unexpected access to local articles, images, or credentials.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The documented purpose omits additional behaviors such as title generation and local article storage/list management. Description-behavior mismatches are dangerous because they prevent informed consent and can hide data retention or content manipulation functions that users did not expect. In a publishing assistant, undisclosed local storage is especially sensitive because article drafts, media, and possibly account-related workflow data may persist on disk.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README uses broad natural-language invocation examples such as writing, rewriting, publishing, and image generation without any trigger constraints, confirmation requirements, or scope limits. In an agent environment, overly generic phrases increase the chance of accidental activation or invocation during normal conversation, which is especially risky because one of the exposed actions is automatic publishing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README advertises automatic article publishing but does not warn that this capability changes externally visible content or may post to a public account. In practice, users or higher-level agents may invoke the skill without appreciating that it performs a real-world, irreversible action, creating a substantial risk of unintended publication, reputational damage, or abuse if the skill is triggered in the wrong context.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
Automatic publishing, scheduling, and bulk sending are high-impact account actions that can affect reputation, compliance, and audience communications. Without an explicit warning and strong confirmation flow, a user may trigger irreversible or mass actions unintentionally. In the context of an official-account assistant, this is more dangerous because misuse could send unwanted content to subscribers at scale from the user's real account.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
Describing login and API authorization without a privacy and security warning normalizes granting broad platform access without explaining the risks. If users provide authorization casually, the skill could gain access to sensitive account operations, content, media, and analytics. In this skill's context, platform authorization directly enables publication and account management, so the absence of clear warnings materially raises the risk of account compromise or overbroad access.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The article describes a skill that records sensitive interpersonal details such as birthdays, preferences, dietary restrictions, allergies, and follow-up obligations, but provides no mention of consent, minimization, retention limits, or access controls. In the context of an assistant skill, this normalizes collection of personal data without privacy safeguards, which can lead to misuse, unauthorized profiling, or exposure of sensitive information.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The article explicitly promotes 'AI 降味' so content '根本看不出来' is AI-generated, and reinforces this again at the end by challenging whether the reader can detect it. This encourages deceptive presentation of AI-generated content without disclosure, which is especially concerning in a publishing assistant because it can facilitate misleading audiences, platform policy evasion, and erosion of trust.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.