Back to skill

Security audit

Webhook Notify

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real webhook notification helper, but it needs Review because it ships broad outbound HTTP helpers and unsafe webhook-secret handling guidance.

Install only if you intend to let the agent send messages to external webhook endpoints. Treat webhook URLs as secrets, avoid logging or displaying them, prefer a secret manager over persistent user environment variables, and do not use the custom HTTP helper or unknown-host URLs unless you have reviewed and approved the destination, payload, and method.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
webhook-functions.ps1:184
Finding

Webhook Credentials Are Exposed Through Console and Batch Output

Content
View full analysis

Vulnerability Details

File Location: webhook-functions.ps1:184-190 and webhook-functions.ps1:209-211
Vulnerability Type: Sensitive information exposure through application output
Risk Level: Medium

Vulnerable Code

powershell
$results += @{
    Url = $url
    Platform = Get-WebhookPlatform -Url $url
    Success = $result
    Timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss"
}
powershell
Write-Host "🧪 测试 $platform Webhook..." -ForegroundColor Cyan
Write-Host "URL: $Url"
Write-Host "消息:$testMsg"

The documentation also explicitly demonstrates displaying the returned URL field:

File Location: SKILL.md:159-160

powershell
$results = Send-Webhook-Batch -Urls $urls -Message "广播"
$results | Format-Table Url, Success, Timestamp

Technical Analysis

Webhook URLs are generally bearer credentials rather than ordinary public endpoints. Depending on the provider, reusable secrets appear in query parameters such as access_token or key, or in path components such as Slack, Discord, Feishu, and Telegram tokens.

Send-Webhook-Batch returns the complete caller-supplied URL in every result object. Test-Webhook-Connection prints the complete URL directly to the console. The documented batch workflow then encourages users to display that field.

Console output and returned objects may be retained in CI logs, shell transcripts, monitoring systems, support bundles, or AI-agent conversation records. No masking or redaction is applied to sensitive query parameters or path segments.

Attack Path

  1. A user configures a valid webhook URL containing an access token, key, or bot secret.
  2. The user invokes Test-Webhook-Connection or Send-Webhook-Batch.
  3. The complete credential-bearing URL is printed or returned in a result object.
  4. A CI system, terminal logger, monitoring service, or agent transcript retains the output.
  5. A party with access to th ...[truncated 673 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not print or return complete webhook URLs. Return only the platform, delivery status, timestamp, and a non-sensitive endpoint identifier.
  2. Introduce a dedicated redaction function that:
    • Removes values for query parameters such as access_token, key, token, and secret.
    • Masks provider-specific secret path components.
    • Preserves only enough information for troubleshooting, such as the hostname and final four characters of an identifier.
  3. Replace Write-Host "URL: $Url" with output such as Write-Host "Platform: $platform" or a safely redacted URI.
  4. Ensure exception and verbose logging also pass URLs through the same redaction function.
  5. Change batch result objects from Url = $url to a field such as Endpoint = Protect-WebhookUrl $url.
  6. Update documentation so examples never recommend displaying raw webhook URLs.
  7. Rotate any production webhook credentials that may already have appeared in persistent logs.

T09 · Insecure Skill Coding Practices

Warning
Location
webhook-functions-simple.ps1:163
Finding

Unrestricted Custom HTTP Requests Permit SSRF-Style Access to Internal Services

Content
View full analysis

Vulnerability Details

File Location: webhook-functions-simple.ps1:163-206
Additional Locations: webhook-functions-utf8.ps1:185-222, webhook-functions-utf8-v2.ps1:143-180, and the unrestricted request sink in webhook-functions.ps1:129
Vulnerability Type: Server-side request forgery and unrestricted outbound requests
Risk Level: Medium

Vulnerable Code

powershell
function Send-WebhookCustom {
    [CmdletBinding()]
    param(
        [Parameter(Mandatory=$true)]
        [string]$Url,
        
        [ValidateSet('GET', 'POST', 'PUT', 'DELETE', 'PATCH')]
        [string]$Method = 'POST',
        
        $Body,
        
        [string]$ContentType = 'application/json',
        [hashtable]$Headers = @{},
        
        [int]$Timeout = 30
    )
    
    $params = @{
        Uri = $Url
        Method = $Method
        TimeoutSec = $Timeout
    }
    
    if ($Body) {
        if ($Body -is [string]) {
            $params.Body = $Body
        } else {
            $params.Body = $Body | ConvertTo-Json -Depth 10
        }
        $params.ContentType = $ContentType
    }
    
    if ($Headers.Count -gt 0) {
        $params.Headers = $Headers
    }
    
    try {
        $response = Invoke-RestMethod @params
        Write-Verbose "HTTP request successful"
        return $response
    } catch {
        Write-Error "HTTP request failed: $_"
        return $false
    }
}

The primary unified sender also accepts an unrestricted URL:

powershell
$response = Invoke-RestMethod -Uri $Url -Method Post -Body $body -ContentType "application/json; charset=utf-8" -TimeoutSec $Timeout

Technical Analysis

The custom HTTP function accepts a caller-controlled URL, method, body, content type, and headers and passes them directly to Invoke-RestMethod. It supports state-changing methods including POST, PUT, PATCH, an ...[truncated 2463 chars]

Remediation
View remediation

Remediation Suggestions

  1. Restrict the standard sender to an explicit allowlist of documented HTTPS webhook hostnames.
  2. Parse destinations with System.Uri and reject malformed URLs, embedded credentials, non-HTTPS schemes, unexpected ports, and fragments.
  3. Resolve the hostname before connecting and reject all resolved loopback, private, link-local, multicast, unspecified, reserved, and cloud-metadata addresses for both IPv4 and IPv6.
  4. Revalidate every redirect destination, or disable redirects entirely for webhook delivery.
  5. Protect against DNS rebinding by connecting only to an already validated resolved address while preserving correct TLS hostname verification.
  6. Remove Send-WebhookCustom from the published skill unless arbitrary HTTP access is an explicit and necessary feature.
  7. If custom HTTP access must remain:
    • Place it behind an explicit opt-in policy.
    • Require user confirmation for unknown hosts and state-changing methods.
    • Restrict allowed methods and headers.
    • Apply destination allowlists configured by an administrator.
    • Limit response size and avoid returning sensitive response bodies by default.
  8. Apply the same validation to Send-Webhook, because URLs categorized as Custom are currently still sent without restrictions.
  9. Add automated tests covering literal and DNS-resolved loopback, private IPv4, private IPv6, link-local, alternative IP representations, redirects, and hostname rebinding scenarios.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:209
Finding

Documentation Recommends Persistent Plaintext Storage of Webhook Secrets

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:209-213
Vulnerability Type: Insecure secret storage guidance
Risk Level: Low

Vulnerable Code

powershell
# 设置环境变量(永久)
[System.Environment]::SetEnvironmentVariable('DINGTALK_WEBHOOK', 'https://...', 'User')
[System.Environment]::SetEnvironmentVariable('WECOM_WEBHOOK', 'https://...', 'User')
[System.Environment]::SetEnvironmentVariable('FEISHU_WEBHOOK', 'https://...', 'User')

Technical Analysis

The documentation recommends persistently storing complete webhook URLs as user-scoped environment variables. These URLs commonly embed reusable access tokens or keys.

User-scoped environment-variable storage is not a dedicated secret-management mechanism. The values persist across sessions in plaintext and may be available to other processes running under the same user account, diagnostic utilities, support bundles, registry or configuration backups, and scripts that enumerate the user's environment.

The repository does not contain actual production credentials in this example. The issue is the insecure operational guidance that encourages users to persist real credentials using this mechanism.

Attack Path

  1. A user follows the documented instructions and replaces the placeholder with a real webhook URL.
  2. The complete credential-bearing URL is persisted at user scope.
  3. Another process, script, diagnostic tool, or attacker operating under the same user account reads the stored value.
  4. The webhook token is extracted from the URL.
  5. The token is reused to send unauthorized notifications through the configured bot or channel.

Impact Assessment

Exploitation requires access to the user's environment or persistent user configuration and does not independently grant elevated operating-system privileges.

A disclosed value grants the capabilities associated with the webhook credential, typically unauthorized message delivery and bot imp ...[truncated 125 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the persistent environment-variable recommendation with a supported operating-system or enterprise secret store, such as Windows Credential Manager, PowerShell SecretManagement, macOS Keychain, a Linux secret service, or a managed vault.
  2. If environment variables are required for automation, recommend injecting them only into the runtime process from a protected CI or orchestration secret store.
  3. Clearly state that webhook URLs are credentials and must not be committed, logged, printed, or stored in shell profiles.
  4. Apply least-privilege access controls to the selected secret store.
  5. Document credential rotation and revocation procedures.
  6. Recommend separate webhook credentials for development, testing, and production to limit the scope of disclosure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (29)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
直接复制 `webhook-functions.ps1` 内容到你的脚本中。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is described as a webhook notification utility for specific chat platforms, but Send-WebhookCustom exposes a generic arbitrary HTTP client that can send attacker-controlled requests to any URL with arbitrary method, headers, and body. In an agent context, this expands capability from notification delivery to general outbound network access, enabling SSRF-like behavior, internal service probing, data exfiltration, or use as a proxy beyond the declared purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function explicitly supports GET, POST, PUT, DELETE, and PATCH, which goes well beyond notification sending and permits arbitrary state-changing HTTP operations against external or internal endpoints. In a skill that is supposed to send webhook notifications, this unjustified capability materially increases abuse potential because an attacker or prompt-injected workflow could repurpose the skill to interact with unrelated APIs or internal services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This is a markdown file, so SQP-2 applies to missing warnings in the skill description. The README immediately instructs users to send messages to arbitrary platform webhooks and includes multiple external webhook examples, but it does not warn that message contents may be transmitted to third-party services or may contain sensitive operational data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该技能描述将“内置模板系统”和“重试机制”列为能力范围的一部分,但函数实现仅接收原始 Message/Title 参数后直接构造 JSON 并发送一次请求。代码中没有模板选择/渲染逻辑,也没有重试循环、退避或重发处理。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

技能清单描述称该工具支持钉钉、企业微信、飞书、Slack、Discord、Telegram,并自动识别平台、统一接口。但 README 中给出的实际函数只匹配 dingtalk、qyapi.weixin.qq.com 和 feishu/larksuite 三类 URL,其它宣称的平台会落入“不支持的 Webhook 平台”异常分支。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is explicitly designed to send message content to third-party webhook platforms, but the documentation does not warn users that any supplied content may leave the local environment and be transmitted to external services. This creates a real risk of accidental disclosure of alerts, logs, host details, or other sensitive operational data when users adopt the examples as-is.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
| **飞书** | ✅ | ✅ | `https://open.feishu.cn/open-apis/bot/v2/hook/***` |
| **Slack** | ✅ | ❌ | `https://hooks.slack.com/services/***` |
| **Discord** | ✅ | ❌ | `https://discord.com/api/webhooks/***` |
| **Telegram** | ✅ | ❌ | `https://api.telegram.org/bot***/sendMessage` |

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples recommend storing webhook URLs in environment variables but do not state that these URLs are effectively bearer secrets, since anyone possessing them can often post messages into the target channel. This omission can lead users to expose webhook tokens via logs, screenshots, shell history, process dumps, or inherited environments.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 317)May include surrounding context.

md
- [钉钉机器人文档](https://open.dingtalk.com/document/orgapp/custom-bot-to-send-group-chat-messages)
- [企业微信机器人文档](https://developer.work.weixin.qq.com/document/path/91770)
- [飞书机器人文档](https://open.feishu.cn/document/ukTMukTMukTM/ucTM5YjL3ETO24yNxkjN)
- [Slack Incoming Webhooks](https://api.slack.com/messaging/webhooks)
- [Discord Webhooks](https://support.discord.com/hc/articles/228383668)
- [Telegram Bot API](https://core.telegram.org/bots/api)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script sets and uses environment variables containing webhook URLs, which function as credentials for external messaging services. While there is a suggestion to use environment variables, there is no explicit warning that these values are sensitive secrets and should not be hardcoded, shared, or committed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The examples begin transmitting data to external webhook endpoints without an explicit warning that execution will send network requests off-host. In a skill context, users may run examples expecting local demonstration behavior, which increases the chance of accidental disclosure of system metadata, alert content, or test data to third-party services.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example explicitly demonstrates sending arbitrary HTTP requests to a user-supplied URL via Send-WebhookCustom, which expands the skill from fixed, declared chat platforms to a general outbound HTTP primitive. In a webhook-notification skill this can enable unintended data exfiltration, SSRF-like access to internal endpoints, or use outside the documented scope if callers pass untrusted URLs or payloads.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger string is very broad and includes many generic notification terms and vendor names, which can cause this skill to activate for common user requests that may not specifically intend to use this tool. In an agent ecosystem, overbroad invocation increases the chance of unintended outbound webhook use, potentially sending sensitive content to external endpoints or bypassing more appropriate tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's user-facing strings and comments are entirely in Chinese, including the title, status messages, and step descriptions. For a general quickstart test script, this imposes a specific language/locale without offering user opt-in or documenting that the skill is region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a unified webhook tool that supports six named platforms plus automatic platform recognition, but the code in this file only contains explicit platform handlers for DingTalk and WeCom, plus a generic custom HTTP request function. There is no implementation here for Feishu, Slack, Discord, Telegram, or any platform auto-detection logic, so the described behavior is broader than the actual code provided.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description promises '自动识别平台,统一接口', which implies callers can use one interface and have the tool infer the destination platform. In this file, callers must choose between distinct functions such as Send-WebhookDingTalk and Send-WebhookWeCom, and no code inspects a webhook URL or payload to identify the platform automatically.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The generic Send-WebhookCustom function can send arbitrary HTTP requests to any URL with caller-controlled method, body, and headers, which exceeds the stated webhook-notification scope. In an agent skill context, this broad network primitive can be abused for SSRF, data exfiltration, unauthorized API calls, or bypassing intended platform-specific safety constraints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a unified webhook tool supporting six named platforms plus automatic platform recognition, but the code in this file provides only platform-specific functions for DingTalk and WeCom and a generic Send-WebhookCustom helper. There is no implementation here for Feishu, Slack, Discord, Telegram, or any auto-detection/unified dispatch behavior, creating a clear description-to-code mismatch.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The generic Send-WebhookCustom function allows arbitrary URLs, methods, headers, and bodies, which expands the skill from a webhook notifier into a general outbound HTTP client. In an agent context, this can enable unintended exfiltration of sensitive data or access to internal network resources if untrusted input can influence the request parameters.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The custom webhook path transmits arbitrary request data to arbitrary endpoints without any built-in warning, confirmation, or policy guardrails. In a skill designed for notifications, this makes silent outbound data transfer easier and increases the risk of accidental or induced leakage of secrets, prompts, or user data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's descriptive comments and multiple user-facing status/error messages are written only in Chinese, which imposes a fixed language on users without opt-in or configuration. Under the policy, locale or language must not be forced unless choice or documented justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The test function prints the full webhook URL directly to user-facing output, which can disclose embedded secrets or bearer-style webhook tokens to logs, terminals, CI output, or shared session recordings. Because webhook URLs commonly act as credentials, anyone who obtains the URL may be able to send spoofed notifications or abuse the integration endpoint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The document forces a specific language for all instructions and examples, with no opt-in, alternative language, or statement that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file consistently presents user-facing instructions in Chinese, which effectively forces a specific language for the skill documentation. Under the stated policy, language-specific behavior should either be optional for users or clearly documented as a justified locale-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.