Back to skill

Security audit

一键知识库 - 微信内容管家

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent Tencent Docs knowledge-base purpose, but it asks users to route downloaded or local content through cloud upload workflows with unclear destination and dependency controls.

Review and replace the Tencent Docs space, index file, and sheet IDs before use; do not upload private files until the destination is confirmed. Install the Tencent Docs dependency only from a trusted, reviewed source, check the granted authorization scopes, and know how to revoke access. Treat the missing scripts as a blocker unless they are supplied from a verified package version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:46
Finding

Unpinned External Skill Installation Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:70
Finding

Fixed Tencent Docs Destination Identifiers May Route User Content to an Unintended Resource

Content
View full analysis
Remediation
View remediation

other

Note
Location
SKILL.md:108
Finding

Referenced Executable Components Are Missing from the Distributed Package

Content
View full analysis
--output-dir python parsers/douyin.py --output-dir python parsers/xiaohongshu.py --output-dir python upload_to_docs.py \ --name "" \ --format "mp4|pdf|pptx|docx|jpg|png|article" \ --source-type "Video Channels|Douyin|Xiaohongshu|WeChat Official Account|local upload" ``` It also claims the following package structure: ```text knowledge-base/ ├── SKILL.md ├── README.md ├── CHANGELOG.md ├── DESIGN.md ├── agent.py ├── add_to_sheet.py ├── upload_to_docs.py └── parsers/ ├── sph.py ├── douyin.py ├── xiaohongshu.py └── wechat_article.py ``` The audited project contains only `SKILL.md`; none of the referenced scripts or supporting files are present. ### Technical Analysis The advertised parsing, downloading, cloud-upload, and index-update behavior cannot execute from the distributed package and cannot be inspected for command injection, unsafe temporary-file handling, credential exposure, upload validation, or authorization defects. This is not direct evidence that malicious code is present. The security concern is that users or Agents may attempt to obtain substitute files from an undocumented source to make the workflow operational. Such replacement code would fall outside the reviewed package and could receive local file paths and Tencent Docs authorization. ### Attack Path 1. The Agent attempts to follow the documented workflow. 2. Execution fails because the referenced parser or upload script is absent. 3. A user or automated process searches for and downloads a similarly named implementation from an external source. 4. The substitute imple ...[truncated 823 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad everyday expressions such as ‘帮我存这个’ and ‘下载这个视频/文章’, which can cause the skill to activate in ordinary conversation without clear user intent to run a workflow that downloads external content and uploads it to Tencent Docs. In this skill’s context, accidental activation is more dangerous than usual because the workflow can fetch remote links, process local files, and write data into a cloud document space, creating privacy and data-handling risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes an automated link/file ingestion pipeline but does not prominently warn users that content is first downloaded to local temporary storage before upload. In this context, that omission matters because users may assume content moves directly to Tencent Docs; local persistence increases exposure to sensitive-data leakage, unintended retention, malware scanning blind spots, and handling of copyrighted or private material.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.