Back to skill

Security audit

公众号留言/评论批量导出 · WeChat Comment Export — 读者留言存为本地 Markdown 归档

Security checks for vulnerabilities and agentic risk

Overview

This skill locally exports WeChat public-account comments through a disclosed browser automation relay, with privacy care needed for the saved comment archive.

Install only if you trust the local browser automation relay and are comfortable letting it operate in a Chrome session already logged in to mp.weixin.qq.com. Store the exported Markdown/JSON carefully because it can contain reader nicknames, comment text, timestamps, regions, and account metadata. The bundled wc3-code.mjs helper is not needed for the documented export flow; avoid invoking it with sensitive data unless you understand the local LLM service it contacts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly relies on local HTTP access to a browser automation relay and is executed via Node, but the manifest does not declare any tool scope or permission boundaries. This creates a trust and review gap: operators cannot easily tell that the skill can use shell, network, and environment capabilities to access an authenticated browser session and export sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill exports reader comments including author nickname, comment content, time, and region into local Markdown files, which is personal data, but the documentation does not provide an explicit privacy warning or handling guidance. Users may unknowingly create unencrypted local archives of sensitive audience data, increasing the risk of accidental disclosure, oversharing, or improper retention.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file embeds a generic LLM relay client that POSTs arbitrary prompt content to a local HTTP service, which is unrelated to the advertised purpose of exporting public-account comments to local Markdown. Even though the endpoint is localhost, it still creates an unexpected data flow path where prompts and potentially sensitive extracted content can be transmitted to another process without tight scope control or feature justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code accepts arbitrary prompts, optional schemas, and session resume values, then forwards them to a local LLM service, effectively providing a general-purpose prompt execution primitive inside a skill whose stated function is read-only comment export. That mismatch expands the skill's capability beyond user expectations and could enable unintended processing, transformation, or exfiltration of comment data through the local service or any backend it is connected to.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The tool silently sends prompt content over HTTP to a local service at execution time without an explicit user-facing notice or confirmation in the command path. In the context of exporting account comments, those prompts may contain sensitive reader messages or metadata, so undisclosed transmission to another process undermines transparency and informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The query string fixes lang=zh_CN, which enforces a specific language/locale in the automated session. Under the policy, locale constraints should either be optional or explicitly justified as region-specific; this file does not present that as a user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.