Back to skill

Security audit

公众号违禁词检测

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent WeChat copy checker, but its URL mode can fetch arbitrary network locations and send the extracted text to RedFoxHub, so users should review it carefully before installing.

Install only if you are comfortable sending scanned copy, uploaded file text, image-extracted text, or fetched webpage text to RedFoxHub. Avoid scanning confidential, regulated, or secret material; use an isolated environment, provide the API key through an explicit environment variable, and do not let the URL feature access localhost, private networks, or cloud metadata endpoints.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/check_sensitive_words.py:180
Finding

Server-Side Request Forgery Through Unrestricted URL Fetching

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:66
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
=2.28.0`, which remains mutable. This issue does not prove that any current dependency is malicious. It creates supply-chain exposure by allowing future, compromised, or unexpectedly incompatible releases to be installed and executed. ### Attack Path 1. A user follows the installation instructions from `SKILL.md`. 2. Pip contacts the configured package index and resolves the latest versions satisfying the unpinned package names. 3. A compromised upstream release, package-index account, index mirror, or dependency can supply attacker-controlled installation or runtime code. 4. The package is installed with the privileges of the user running pip. 5. The ...[truncated 841 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check_sensitive_words.py:267
Finding

Unsanitized API-Provided HTML Propagated to Downstream Output

Content
View full analysis
(.*?)', api_content ) )) html_content = re.sub( r'', '', api_content ) ``` The resulting content is returned without comprehensive sanitization: ```python for fpw in false_positive_words: escaped = re.escape(fpw) html_content = re.sub( rf'{escaped}', fpw, html_content ) result = { "status": "success", "platform": "公众号", "original_content": original_content, "sensitive_words": sensitive_words, "prohibited_words_type": prohibited_words_type, "word_count": len(sensitive_words), "html_content": html_content } ``` ### Technical Analysis The remote API response is treated as trusted HTML. The script rewrites only three recognized opening `` forms and removes certain false-positive spans. It does not escape other markup or apply an HTML sanitizer. As a result, arbitrary tags and attributes present in `api_data["content"]` survive into `html_content`. If a downstream agent interface, browser, report generator, or chat client renders this value as HTML, active content may execute or influence the rendered document. Potentially dangerous content includes: - Event-handler attributes such as `onerror` or `onclick` - Active elements such as scripts, if the renderer permits them - Mali ...[truncated 1913 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Tainted flow: 'headers' from os.getenv (line 96, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/check_sensitive_words.py (reported line 110)May include surrounding context.

python
last_error = None
    for attempt in range(max_retries + 1):
        try:
            response = requests.post(API_URL, headers=headers, json=payload, timeout=30)

            if response.status_code >= 500 and attempt < max_retries:
                import time

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README mentions encrypted transmission and that copy is not stored locally, but it does not clearly and explicitly warn that submitted text, uploaded file contents, image-extracted text, and fetched URL content are sent to a third-party external detection service. Users may unknowingly submit sensitive business drafts, regulated content, or personal data off-platform, creating confidentiality, privacy, and compliance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README says users can 'Describe what you need in plain language—no fixed commands to memorize,' which makes activation scope ambiguous and suggests the skill may respond to a wide range of ordinary language. While examples are provided later, this line does not define clear trigger boundaries or exclusion conditions.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.en.md (reported line 60)May include surrounding context.

md
### Quick Phrase Reference

| Intent              | Example prompt                                                                                                | Outcome                                               |
| ------------------- | ------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------- |
| Paste copy to check | "Check this draft for prohibited words: This whitening miracle really works—you'll see results in three days" | Hit highlights, replacement table, and optimized copy |
| Upload a file       | Upload a TXT, DOC, or DOCX file and ask for WeChat prohibited-word detection                                  | File content is read and checked automatically        |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states '直接用自然语言描述需求,无需记忆固定命令', which encourages free-form requests rather than specific trigger phrases or constraints. For a markdown skill description, this is an ambiguous activation condition that could overlap with common everyday speech and lead to unintended invocation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares dependencies and describes behavior that uses environment variables, local file reading, and outbound network access, but it does not declare any explicit tool scope or permission boundaries. This weakens least-privilege controls and can cause the host agent to grant broader capabilities than users expect, especially because the skill reads local content and sends extracted text to a remote API.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill description and all user-facing instructions are written exclusively in Chinese and are framed around a fixed WeChat public-account workflow, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script silently reads ~/.bashrc, ~/.zshrc, ~/.bash_profile, and ~/.profile to recover credentials, which exceeds what users typically expect from a text-scanning utility. Reading unrelated local configuration files can expose secrets and normalizes covert credential discovery behavior, especially risky in an agent/skill context where users may not inspect code closely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script reads local shell configuration files to extract an API key without explicit user disclosure or consent. Even though it targets a named variable, accessing shell init files is a sensitive local-read capability that can surprise users and may expose credentials stored in those files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The tool sends full user-provided content to a third-party remote API for analysis without an explicit warning, confirmation, or privacy notice. If users scan drafts, internal documents, logs, or scraped web content, sensitive or proprietary data may be disclosed outside the local environment unexpectedly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This skill's core behavior is to transmit user content to an external service for scanning, so the transmission is intentional and functionally necessary; however, it still creates a real data exposure risk because content may include confidential drafts, documents, or web-extracted text. In this skill context, the danger is heightened by the lack of up-front disclosure and the broad input sources it can process.

Content

Scanner excerpt · scripts/check_sensitive_words.py (reported line 110)May include surrounding context.

python
last_error = None
    for attempt in range(max_retries + 1):
        try:
            response = requests.post(API_URL, headers=headers, json=payload, timeout=30)

            if response.status_code >= 500 and attempt < max_retries:
                import time

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The line '平台固定为公众号,无需手动指定' hard-codes a single platform context in the user-facing instructions. This can be a natural-language policy concern because it removes user choice rather than offering an explicit opt-in or clearly framed locale/platform selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script emits user-facing status and error messages in Chinese, such as the dependency error string, with no option to select another language. This is a natural-language policy concern because the tool imposes a locale on all users rather than offering language choice or documenting a justified region-specific restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The docstring says the function supports "DOC、DOCX、TXT等文本类型文件," and the unsupported-type error says it supports "图片、TXT、DOC、DOCX等文本类型文件," but the code only handles .doc/.docx via python-docx and several text-like extensions. There is no image extraction or OCR logic, and .doc support is not truly implemented by python-docx in the same way as legacy Word binaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Argument descriptions and user-facing error messages throughout the CLI are written only in Chinese, which forces a specific language experience. There is no indication that users can choose locale or that the skill is intentionally restricted to a Chinese-language context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.