Back to skill

Security audit

公众号热门账号推荐

Security checks for vulnerabilities and agentic risk

Overview

This WeChat ranking skill is mostly purpose-aligned, but it reads shell profile files for API keys and claims scheduled subscriptions that the package does not actually implement.

Install only if you are comfortable with a third-party RedFoxHub API integration, local shell-profile scanning for REDFOX_API_KEY, and generated HTML reports that execute JavaScript. Treat the subscription feature as unsupported unless the publisher adds a real scheduler and subscription storage, and prefer setting REDFOX_API_KEY only in the current environment rather than relying on profile-file discovery.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
references/core_workflow.md:5
Finding

Agent behavior override and deceptive subscription confirmation

Content
View full analysis
智能体默认输出,必须100%按标准模板输出 ``` The same forced-output behavior is reinforced in `SKILL.md:384`: ```markdown - 脚本输出的 `formatted_markdown` 字段已包含完整的标准模板格式,直接原样输出即可,禁止自行拼装或修改格式 ``` ### Technical Analysis The Skill explicitly attempts to assign its own instructions a higher priority than the agent's default behavior. It requires the agent to reproduce a fixed response verbatim rather than treating the template as untrusted Skill-provided content. This instruction is especially problematic for subscriptions. The repository contains no scheduler, persistent subscription database, callback registration, delivery service integration, or scheduled-task implementation. Nevertheless, the workflow directs the agent to state that a subscription was successfully created and that future messages will be delivered. The mandatory formatted output also includes a fixed feature-promotion block through `FEATURE_PROMPT` in `scripts/gzh_growth_fetcher.py:515-567`. This creates an output-injection channel that promotes further engagement regardless of whether the host agent considers the content appropriate or the advertised functionality is available. ### Attack Path 1. A host agent loads `SKILL.md` and `references/core_workflow.md`. 2. The Skill asserts that its formatting instructions take priority over the agent's normal behavior. 3. After a ranking query, the gen ...[truncated 944 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gen_gzh_html.py:518
Finding

Stored JavaScript execution in generated HTML reports

Content
View full analysis
{page_title} ``` The serialized data is inserted directly into JavaScript: ```javascript (function() { var RAW = {js_data}; ``` Untrusted fields are then concatenated into markup: ```javascript var searchUrl = 'https://open.weixin.qq.com/qr/code?username=' + encodeURIComponent(d.accountId || d.accountName); var avatar = d.accountAvatar || ''; var accountName = d.accountName || '--'; var accountId = d.accountId || ''; html += '
' + '
' + rankHtml + (avatar ? '' : '') + '
' + '
' + accountName + '' + '发布' + publishCount + '' + '
' + '
ID: ' + accountId + ' | 综合评分: ' + compositeScore + '
' + '
' + '
'; ``` The resulting string is installed as active HTML: ```javascript document.getElementById('accountList').innerHTML = html; ``` ### Technical Analysis `json.dumps()` produces valid JSON but does not make a value safe for direct placement inside an HTML `
Remediation
View remediation
``` Populate its text safely and parse it using `JSON.parse(element.textContent)`. 6. When embedding JSON in HTML, encode at least `<`, `>`, `&`, U+2028, and U+2029. In particular, replace `<` with `\u003c` to prevent `` termination. 7. HTML-escape `page_title`, `category`, `fetch_time`, and `time_range` before inserting them into static markup. 8. Add a restrictive Content Security Policy that blocks inline event handlers and limits script, image, and connection sources. 9. Add regression tests containing ``, quotation marks, angle brackets, event-handler attributes, and malformed URLs in every remotely controlled field. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/gzh_growth_fetcher.py:256
Finding

Excessive scanning of shell profile files for API credentials

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/gen_gzh_html.py:528
Finding

Generated reports execute third-party CDN scripts without integrity verification

Content
View full analysis
``` ### Technical Analysis Every generated report references executable JavaScript hosted by a third-party CDN. The URLs specify library versions, but the report does not provide Subresource Integrity hashes, a restrictive Content Security Policy, or local audited copies. Consequently, the executable behavior of an already generated report depends on content delivered by the CDN at the time the report is opened. A CDN compromise, origin compromise, account takeover, or delivery-path failure could cause unauthorized JavaScript to execute in the report. This network access is also inconsistent with the expectation that an exported HTML report is self-contained or independently usable. Even when `--input_json_file` avoids the RedFox API, opening the resulting report still performs outbound requests for these dependencies and potentially for avatar images. ### Attack Path 1. A report is generated with references to the two CDN-hosted scripts. 2. The victim opens the report while connected to a network. 3. The browser requests the JavaScript files from `cdnjs.cloudflare.com`. 4. If the dependency content or delivery path has been compromised, the browser receives modified JavaScript. 5. Because no integrity hash is present, the browser accepts and executes the modified code. 6. The injected code runs with access to the generated report's DOM and browser networking capabilities. ### Impact Assessment A successful supply-chain compromise could allow arbitrary JavaScript execution in every affected report opened while the malicious dependency is served. The attacke ...[truncated 438 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

This mismatch is security-relevant because the skill presents itself as a ranking/reporting tool while also instructing behavior that touches sensitive local files for credentials, without matching permission declarations. Even if the overclaimed HTML/report and subscription features are mostly integrity/usability issues, the hidden local credential lookup and network use materially increase risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

This mismatch is security-relevant because the skill presents itself as a ranking/reporting tool while also instructing behavior that touches sensitive local files for credentials, without matching permission declarations. Even if the overclaimed HTML/report and subscription features are mostly integrity/usability issues, the hidden local credential lookup and network use materially increase risk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.en.md (reported line 41)May include surrounding context.

md
- **Scheduled Updates**: Daily chart refreshes at 17:30, weekly chart every Monday at 17:30, monthly chart on the 3rd at 23:00
- **Controlled Lookback**: Daily charts span the past 7 days, weekly the past 3 weeks, monthly the past 3 months — out-of-range requests auto-adjust with a prompt
- **Data Consistency**: The ranking table and visual report share the same data source, with identical order and content
- **On-Demand Expansion**: The ranking table outputs directly without confirmation; analysis, reports, and subscriptions are user-initiated

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The phrase "Just describe your need in plain language — no commands to memorize" indicates very open-ended invocation behavior for a markdown file. Without explicit limits, negative examples, or a narrow activation context, common ranking-related everyday requests could unintentionally match this skill.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.en.md (reported line 62)May include surrounding context.

md
### Quick Reference

| Intent                          | Example Phrase                         | Result                                                                                   |
| ------------------------------- | -------------------------------------- | ---------------------------------------------------------------------------------------- |
| Query daily chart by category   | "Show the tech category daily ranking" | Outputs the Tech & Digital daily TOP 50 with composite scores and engagement metrics     |
| Query weekly chart by category  | "This week's food category ranking"    | Outputs the Food & Dining weekly TOP 50 with time range noted                            |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.en.md (reported line 83)May include surrounding context.

md
## Use Cases

| Scenario                   | Role                    | Example Query                              | Benefit                                                                                |
| -------------------------- | ----------------------- | ------------------------------------------ | -------------------------------------------------------------------------------------- |
| Daily operations reference | Account Operator        | "Show tech category daily ranking"         | Compare posting frequency and engagement rates to benchmark and optimize topic cadence |
| Competitor tracking        | Brand Marketing Manager | "This week's FMCG category ranking"        | Track competitor ranking shifts and content direction to adjust your own strategy      |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states users can interact via unrestricted natural language, which makes the skill’s invocation boundary overly broad and ambiguous. In an agent environment, this can cause accidental triggering on unrelated prompts and increase the chance the skill processes unintended user input, leading to mis-execution or unsafe downstream actions such as subscriptions or report generation without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope or permissions even though the documentation instructs use of environment access, local file reads/writes, and remote network access. This creates a transparency and consent gap: an installer or runtime may permit broader operations than the manifest communicates, increasing the risk of unintended secret access or outbound data use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly states that its output formatting takes highest priority over the agent’s default behavior, which can override user preferences and platform safety/UX norms. While this is mostly a policy and control issue rather than direct code execution, rigidly forcing a response style can be abused to suppress warnings, reduce transparency, or interfere with system-mandated disclosures in downstream interactions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The helper _get_redfox_api_key() searches the user's shell/profile files (.zshrc, .bashrc, PowerShell profiles, etc.) and parses them for API credentials. This is broader filesystem access than required for generating an HTML report and can expose secrets from local configuration without clear, explicit user consent; in an agent-skill context, silent credential harvesting is especially risky even if the key is only intended for the target service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script reads sensitive local configuration files to discover REDFOX_API_KEY but does not present an explicit warning or confirmation before doing so. In a skill environment, users may not expect a ranking-report generator to inspect shell profiles, making this a privacy and secret-handling issue that could normalize overbroad access to local files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script's description, help text, reminders, errors, and output templates are written entirely in Chinese, and no option is provided for users to select another language. This is a natural-language locale constraint that applies across the skill behavior without opt-in or justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script enumerates and reads multiple shell/profile files to recover an API key, which is unnecessary broad local file access for a data-fetching skill. Even though it only looks for REDFOX_API_KEY, this behavior accesses sensitive user configuration without explicit consent and creates a precedent for harvesting secrets from local environment setup files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code reads shell profile files to extract credentials without explicit warning or runtime confirmation from the user. Shell profiles often contain secrets and other sensitive configuration, so silently inspecting them expands the trust boundary and can expose users to credential disclosure or unexpected local data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script constructs headers containing X-API-KEY and sends category and date query data to https://redfox.hk. Although network access is central to the tool's purpose, there is no explicit user disclosure in the code or top-level description that user-supplied query inputs and authentication credentials are transmitted to a third-party service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says the skill supports deep single-account analysis, HTML visual report export, and day/week/month subscription push. In this file, the code only retrieves ranking data, formats tables/analysis text, and emits prompt text claiming those extra functions; there is no implementation for export generation, subscription registration, or scheduled push delivery here.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The statement that "keywords automatically match the right category" suggests broad matching behavior but does not define allowed keywords, category names, or disambiguation rules. In a markdown skill description, this can create ambiguity about when the skill should activate and what inputs are in scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Keyword-based automatic category matching without documented constraints can cause ambiguous routing, where partial or incidental terms trigger the wrong category or invoke the skill unexpectedly. While this is not a direct code-execution issue, it can produce incorrect results, confuse users, and make agent behavior less predictable in multi-skill contexts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

L355-L357 明确写明 REDFOX_API_KEY “仅通过环境变量读取”,给人的安全与实现预期是不会读取本地配置文件内容。但 L050-L056 同时定义了“三级认证回退”,其中包含自动读取 ~/.zshrc、~/.bashrc、~/.bash_profile 和 PowerShell Profile,这与“仅通过环境变量读取”的表述直接冲突。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The workflow instructs the agent to redirect output into a fixed temporary file path under /tmp without warning the user or documenting data-handling risks. Even if the data is not highly sensitive, silent file creation can leak query results across processes, enable race/symlink issues in shared environments, or violate user expectations about persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill directs generation of an HTML output file and specifies a naming convention, but does not require any user warning or consent before creating that artifact. Unannounced file generation can surprise users, consume storage, and create a persistence channel for potentially sensitive query results; if the HTML includes unsanitized content from external data, it could also increase exposure when opened locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script creates and writes an HTML file to the provided or auto-generated path. While file output is part of the tool's purpose, there is no explicit user disclosure immediately before the write explaining where data will be saved, beyond general status messages after the fact.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.