Back to skill

Security audit

微信小程序 TabBar 图标生成

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently generates WeChat Mini Program tab icons and updates app.json, with ordinary caution needed for project file edits and installing Pillow.

Install this for Chinese-language WeChat Mini Program projects where you want generated tabBar icons. Review the target project path and app.json changes before running it, and prefer installing Pillow in a virtual environment with a pinned version if you need reproducible builds.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
SKILL.md:22
Finding

Unpinned Third-Party Pillow Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 22
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Low

Vulnerable Code Snippet:

markdown
- Python 3 + Pillow (`pip install pillow`)

Technical Analysis

The skill directs the user or agent to install Pillow from the Python Package Index without specifying a reviewed version or validating an integrity hash. The package resolved by pip install pillow can therefore change over time, making installations non-reproducible and automatically trusting whichever release the package index currently serves.

This is a supply-chain weakness rather than evidence that Pillow itself is malicious. If the package distribution channel or a future release were compromised, package installation could execute attacker-controlled installation or build logic with the privileges of the account running pip. The instruction does not use an explicitly unsafe or unofficial source, and no dependency-confusion package name or known malicious dependency was identified, so the practical risk is low.

Attack Path

  1. An attacker compromises the upstream Pillow distribution account, release process, or package-index delivery path.
  2. The attacker publishes or serves a malicious release under the legitimate package name.
  3. A user or agent follows the skill instruction and runs pip install pillow.
  4. Pip resolves the unpinned dependency to the compromised release.
  5. Malicious installation, build, or imported runtime code executes in the installation environment.

This path depends on a separate upstream supply-chain compromise; the audited project does not itself retrieve a custom remote payload or contain malicious executable code.

Impact Assessment

Successful exploitation could execute arbitrary code with the permissions of the user running pip. Depending on that user's privileges and environment, this could permit access to ...[truncated 458 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin Pillow to a specifically reviewed version in a dependency file, for example:

    text
    Pillow==REVIEWED_VERSION
    
  2. Generate and enforce cryptographic hashes using a lock workflow such as pip-tools, then install with hash verification:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Install the dependency inside a dedicated virtual environment rather than the system Python environment:

    bash
    python -m venv .venv
    .venv/bin/python -m pip install --require-hashes -r requirements.txt
    
  4. Configure an approved package index explicitly and avoid untrusted mirrors or additional indexes.

  5. Periodically review and update the pinned version after checking release provenance and known vulnerabilities. Regenerate verified hashes whenever the version changes.

  6. Document that dependency installation must run as an unprivileged user and must not use sudo or an administrator account.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly states it will automatically write to app.json and generate files under images/, but it does not present a clear user-facing warning or confirmation requirement before modifying project files. This creates a real integrity risk: users may trigger the skill expecting advice or code generation, but instead receive direct changes to application configuration and assets.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill declares trigger phrases including broad terms like “tab 图标”, which can plausibly appear in ordinary conversation and increase the chance of unintended invocation. Because the skill performs file reads/writes and project modification, accidental activation could lead to unreviewed changes to app.json and asset generation in the wrong project context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

A description written only in Chinese without declaring locale scope can cause activation and interpretation issues in multilingual environments. This can lead to accidental triggering, user misunderstanding, or misuse by agents that rely on metadata to route skills appropriately.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says the skill should be used for broad phrases like '生成 tabBar 图标' or 'tab 图标' but does not clearly constrain when it should activate or what project context must be present. Overly broad activation can cause the skill to trigger in unintended contexts and modify files such as app.json when the user did not specifically request this exact operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.