Back to skill

Security audit

微信公众号媒体下载器 WeChat Media Downloader

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly designed to capture and download WeChat media through a logged-in Chrome session, but that session access and local capture behavior need careful review before use.

Install only if you are comfortable letting the agent attach to a Chrome session you manually verified or logged into, capture page-derived URLs and text, and save media plus temporary artifacts locally. Use a dedicated browser profile, keep output in a private directory, review/delete temporary HTML, text, JSON, and profile files afterward, and avoid passing untrusted video URLs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
yt-dlp== ``` 2. Generate a lock file containing hashes for direct and transitive dependencies, and require hash verification: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Install dependencies in a dedicated virtual environment instead of the user's shared package environment: ```bash python3 -m venv .venv . .venv/bin/activate python3 -m pip install --require-hashes -r requirements.txt ``` 4. Document the expected package index and disallow untrusted extra indexes. 5. Review dependency updates before changing the lock file. 6. Remove `yt-dlp` from the standard installation command if it remains optional and is not used by the bundled scripts. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/download_wechat_media.py:22
Finding

Unrestricted Video URL Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented purpose focuses on downloading media, but the behavior also includes saving full page HTML and extracted page text locally. That broader data capture can expose article content, account-scoped page data, or session-related material beyond the minimum needed for media download, especially when paired with a logged-in browser session.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented purpose focuses on downloading media, but the behavior also includes saving full page HTML and extracted page text locally. That broader data capture can expose article content, account-scoped page data, or session-related material beyond the minimum needed for media download, especially when paired with a logged-in browser session.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow explicitly instructs the user to complete manual verification/login in a visible Chrome session, attach via remote debugging, and then capture real media URLs to download content that is otherwise protected by anti-automation controls. This is not a neutral browser-automation pattern: it is a step-by-step bypass workflow for platform defenses and protected media extraction, which materially increases the risk of unauthorized access, account/session misuse, and terms-of-service violations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes network access, reading page content, and writing downloaded media and captured HTML to disk, but it does not declare any explicit tool scope or permission boundaries. In practice this weakens review and containment, because a consumer of the skill cannot easily determine or enforce what file and network operations are intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Connecting to a live Chrome remote debugging session and capturing request/response traffic plus page HTML can expose authenticated session data, tokens, cookies, and private article content from the user's logged-in browser context. This is especially sensitive because the workflow explicitly asks the user to complete verification/login first, making the captured session more privileged and therefore more dangerous if mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file describes automatic downloading, title extraction, renaming, and output organization, as well as connecting to Chrome remote debugging, but does not explicitly warn about the resulting local file writes or browser-session interaction. For a markdown skill description, behaviours that affect user data or system state should be clearly disclosed as warnings.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/github-readme-zh.md (reported line 34)May include surrounding context.

md
- 专门适配微信公众号媒体页面
- 支持视频 + 多段音频
- 能处理微信“环境异常 / 去验证”拦截
- 优先用户级安装,尽量不要求 sudo
- 支持中文标题提取与重命名
- 最终输出成干净目录,便于归档

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script attaches to Chrome DevTools on localhost and passively captures request and response URLs from an existing browser context, which may expose authenticated network activity beyond the target article. Because it reuses a live browser session to bypass WeChat anti-bot checks, the skill context makes this more dangerous: cookies, tokens, and URLs from the user's active browsing context may be observed without strong scoping or user-facing disclosure.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · scripts/capture_wechat_media.py (reported line 29)May include surrounding context.

python
out = Path(args.out)
    out.mkdir(parents=True, exist_ok=True)

    info = json.loads(urllib.request.urlopen('http://127.0.0.1:9222/json/version', timeout=10).read().decode('utf-8'))
    ws = info['webSocketDebuggerUrl']

    captured = []

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script persists full page HTML, extracted body text, and captured media-related URLs to disk, which can include sensitive article content, tracking tokens, signed media URLs, or user-visible data from the browsing session. In the context of attaching to a real Chrome session for manual verification, this creates an unnecessary data retention/privacy risk if the output directory is shared, reused, or insufficiently protected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script downloads a video and multiple audio files from remote URLs and writes them into the user-specified final directory. While it prints a manifest at the end, there is no prior user-facing disclosure, confirmation prompt, or explanatory comment/docstring warning that network access and local file creation will occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs creation of local files including downloaded media and temporary artifacts, but it does not clearly enumerate what will be written or how cleanup is handled. This can lead to unintentional storage of sensitive or copyrighted material, disk clutter, and confusion about residual files left on the system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest declares a specific language locale ("zh-CN") for the skill, which can constitute a language policy violation when no user choice or opt-in is provided. The surrounding metadata does not document that the locale restriction is optional or justified as a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The phrase '主要面向中文用户' indicates a language or locale preference in the natural-language description. Under the policy, forcing or preferring a specific language without explicit user opt-in or clear region-specific justification can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The description states this is a skill for the Chinese WeChat public-account scenario, and later says it is suitable for Chinese users directly. This presents a language/locale-specific framing without explicitly offering user choice or explaining a policy-justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description says it will automatically download media, rename files, and organize output into a folder, which are file-writing operations that affect user data. The markdown does not include any caution, confirmation expectation, or disclosure about where files are saved or that local files will be created/renamed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.