Back to skill

Security audit

微信公众号文章提取|公众号文章转文字(全文 + 图片文字 OCR)

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently sends a user-provided WeChat article link to LinkDigest for OCR and Markdown extraction, with API-key use, costs, and caching disclosed.

Install only if you are comfortable sending public WeChat article links and your LinkDigest API key to linkdigest.dev. Do not submit private or internal links, keep the key in environment/config rather than chat, and use the documented mp.weixin.qq.com workflow to avoid unexpected billing or broader platform processing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly requires access to environment variables, shell execution, and outbound network access, but it does not declare an explicit tool/permission scope. That creates a governance gap: a host agent may grant broader capabilities than intended, making it harder to sandbox or review what the skill is allowed to do. In this context the skill is designed to send user-supplied URLs and an API key to a third-party service, so missing scope declarations materially increase operational risk even if the documented behavior appears benign.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill instructs the agent to transmit a user-provided article URL and a bearer API key to an external service at linkdigest.dev. This is an actual data egress path and credential use path; while it is central to the skill's stated purpose, it still exposes user-supplied content and a secret to a third party and relies on that external service for processing and caching. The surrounding text explicitly says results may be cached and shared for the same public link, which increases privacy sensitivity rather than reducing it.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

没有 Python 时直接调 HTTP:

bash
curl -sS -X POST https://linkdigest.dev/api/v1/digest \
  -H "Authorization: Bearer $LINKDIGEST_API_KEY" -H "Content-Type: application/json" \
  -d '{"url": "https://mp.weixin.qq.com/s/xxxxxxxx", "format": "markdown"}'
# 返回 202 时:curl -sS "https://linkdigest.dev/api/v1/digest/<jobId>?wait=20&format=markdown" -H "Authorization: Bearer $LINKDIGEST_API_KEY"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s user-facing natural language is entirely in Chinese, including the top-level docstring, usage text, errors, and argument descriptions. The policy for this category flags language/locale constraints when a skill forces a specific language without user opt-in, and this file does not offer a general language-selection mechanism for the CLI experience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a WeChat public-article reader focused on mp.weixin.qq.com article extraction. The CLI help text instead states the tool reads links from multiple platforms including 小红书/抖音/TikTok/YouTube/X/公众号文章, which actively contradicts the skill's declared single-purpose scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
49% confidence
Finding

The module docstring says '只连 linkdigest.dev 这一个域名', presenting a strict network/intended-dependency boundary. However, the implementation includes a fallback import of certifi at L074-L079, which contradicts the earlier claim in documentation that it uses only the Python standard library and only interacts with that single domain if certifi must be installed separately as suggested in the user-facing hint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.