Back to skill

Security audit

Wechat Content Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only WeChat content template with disclosed monetization guidance, but users should review promotional claims before publishing.

Install this only if you want Chinese WeChat Official Account content and monetized/affiliate-style drafts. Before publishing, remove or edit any unverified claims such as personal-use language, repurchase claims, or statements that a link is in the comments, and add sponsorship or affiliate disclosures where required.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:47
Finding

Hard-Coded Promotional Call-to-Action Hijacks Generated Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47-53
Vulnerability Type: Fixed advertising and traffic-diversion instruction
Risk Level: Medium

Vulnerable Snippet

The following is an English rendering of the instruction at the identified location:

text
Article structure:
1. Opening hook (100 characters): relatable pain point or counterintuitive discovery
2. Product introduction (200 characters): appearance, specifications, and core features
3. Usage experience (300 characters): personal impressions and details
4. Comparison (200 characters): differences from competing products
5. Purchase advice (100 characters): suitable and unsuitable audiences
6. Ending CTA: "The link is in the comments; get it yourself 👇"

Technical Analysis

The product-review template mandates a fixed promotional call-to-action that claims a link is available in the comments. The instruction is not conditioned on the user requesting promotional language, providing a destination, or confirming that a comment-section link exists.

Affiliate content is within the Skill's declared functionality, but automatically inserting an unverified traffic-diversion statement exceeds the minimum behavior necessary to generate reviews. It alters generated output toward monetization and external redirection regardless of whether that behavior is appropriate for the specific request.

This is best classified as instruction hijacking because loading and following the Skill can cause the agent to inject an attacker-authored promotional directive into otherwise ordinary content. The reviewed package contains no executable scripts, remote payload retrieval, credential access, persistence, or privilege-escalation mechanism.

Attack Path

  1. A user invokes the Skill to generate a WeChat product review.
  2. The agent follows the predefined product-review structure.
  3. The fixed ending instruction is incorporated without requiri ...[truncated 1071 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the mandatory fixed call-to-action from the default review template.
  2. Include promotional language only when the user explicitly requests affiliate or sponsored content.
  3. Require the user to provide and approve the exact destination before referring readers to a link.
  4. Do not claim that a link exists in a comment, article, profile, or other location unless its presence has been confirmed.
  5. Use a neutral placeholder during drafting, such as [USER-APPROVED LINK LOCATION], rather than an assertion presented as fact.
  6. Require clear affiliate or sponsorship disclosures when commercial links are included.
  7. Separate ordinary product-review generation from monetized-content generation so that the least promotional mode is used by default.
  8. Add an instruction prohibiting fabricated personal-use claims, purchase history, endorsements, and link availability.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is framed as generating content specifically for the Chinese WeChat ecosystem and presents those assumptions as defaults rather than an explicit user-selected mode. If activated unexpectedly, it can force region-specific language, platform conventions, and monetization tactics that may be irrelevant, misleading, or noncompliant for users in other locales or for non-Chinese audiences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger examples are broad, natural-language phrases such as asking for help creating content or what to post on WeChat, which can cause the skill to activate in routine conversations beyond explicit user intent to use this specific skill. Unintended activation can steer outputs toward monetized affiliate-style content and China/WeChat-specific guidance without sufficient user consent or contextual fit.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.