Back to skill

Security audit

content-factory

Security checks for vulnerabilities and agentic risk

Overview

The skill matches a WeChat content workflow, but it handles credentials and publishing authority in unsafe, under-scoped ways that require careful review before use.

Do not install this version unless you are comfortable reviewing and fixing its credential handling first. Remove hardcoded WeChat secrets, replace credential checks with non-disclosing status checks, avoid printing .env files or passing secrets on the command line, require an HTTPS allowlisted proxy if proxying is used, and make promotional CTA/reference behavior opt-in. Rotate any WeChat, Tavily, Brave, or GLM credentials if these scripts or checks have already been run in logged environments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:1147
Finding

Mandatory Commercial Content Injection Into User Deliverables

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/create_default_cover.py:27
Finding

Hardcoded WeChat Account Credentials in Source Code and Documentation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:149
Finding

Mandatory Tool Check Prints Complete Search API Keys

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/wechat_publish.py:90
Finding

Unrestricted Proxy Configuration Can Exfiltrate WeChat Credentials and Unpublished Content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check_env.py:68
Finding

Environment Checker Discloses Credential Prefixes to Logs

Content
View full analysis
10 else value print(f" {key}: {masked_value}") print(f" ({description})") else: print(f" {key}: Not set") print(f" ({description})") all_set = False # Check optional keys print("\nOptional (for WeChat auto-publishing):") wechat_configured = True for key, description in optional_keys.items(): value = os.environ.get(key) if value and value not in ['your-api-key-here', 'your-app-id-here', 'your-app-secret-here']: masked_value = value[:10] + "..." if len(value) > 10 else value print(f" {key}: {masked_value}") print(f" ({description})") ``` The same prefix-disclosure pattern also appears at `scripts/check_env.py:45`. ### Technical Analysis The checker displays the first ten characters of each configured API key or application secret. Although this is described as masking, ten characters constitute a substantial and stable credential fragment. For shorter values, the code prints the entire value. A configuration checker only needs to report whether a value is present and whether it is still a placeholder. Revealing any portion of the credential is unnecessary. The output may be stored in shell history, CI logs, Agent tool transcripts, support tickets, screenshots, or monitoring systems. Prefixes can assist credential correlation, identify providers or accounts, and reduce the unknown search space if another partial disclosure occurs. ### Attack Path 1. A user or automated workflow runs `scripts/check_env.py`. 2. The script reads credent ...[truncated 822 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (200)

Tainted flow: 'TOKEN_URL' from os.environ.get (line 96, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The request target for token retrieval is derived from WECHAT_PROXY_URL, an environment-controlled value, and the request includes highly sensitive app credentials as query parameters. If that proxy URL is pointed to an attacker-controlled host, the script will exfiltrate APPID and APPSECRET and trust the returned access token response, enabling credential theft and account takeover of the WeChat publishing workflow.

Content

Scanner excerpt · scripts/wechat_publish.py (reported line 156)May include surrounding context.

python
}

        try:
            response = requests.get(TOKEN_URL, params=params, headers=self._proxy_headers, timeout=10)
            response.raise_for_status()
            data = response.json()

Tainted flow: 'url' from os.environ.get (line 552, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

Cover image upload uses an endpoint derived from the environment-controlled proxy base and includes the access token in the URL while transmitting local file contents. If misconfigured or attacker-influenced, the script will upload local media to an untrusted endpoint, leaking data and enabling token theft.

Content

Scanner excerpt · scripts/wechat_publish.py (reported line 205)May include surrounding context.

python
try:
            with open(image_path, 'rb') as f:
                files = {'media': (image_path.name, f, 'image/png')}
                response = requests.post(url, files=files, headers=self._proxy_headers, timeout=60)
                response.raise_for_status()
                data = response.json()

Tainted flow: 'url' from os.environ.get (line 552, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

Content image upload sends local files to a request target ultimately controlled by WECHAT_PROXY_URL, along with the access token in the query string. This creates a direct exfiltration path for article assets and credentials to an attacker-controlled proxy, with little user visibility beyond normal publish behavior.

Content

Scanner excerpt · scripts/wechat_publish.py (reported line 253)May include surrounding context.

python
try:
            with open(image_path, 'rb') as f:
                files = {'media': (image_path.name, f, 'image/png')}
                response = requests.post(url, files=files, headers=self._proxy_headers, timeout=60)
                response.raise_for_status()
                data = response.json()

Tainted flow: 'url' from os.environ.get (line 552, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The draft creation endpoint is built from an environment-controlled proxy base, so article content, metadata, and the access token embedded in the URL may be sent to an attacker-controlled service. This allows interception or modification of content and abuse of the bearer token for unauthorized WeChat API operations.

Content

Scanner excerpt · scripts/wechat_publish.py (reported line 518)May include surrounding context.

python
json_data = json.dumps(payload, ensure_ascii=False).encode('utf-8')
            headers = {'Content-Type': 'application/json; charset=utf-8'}
            headers.update(self._proxy_headers)
            response = requests.post(url, data=json_data, headers=headers, timeout=30)
            response.raise_for_status()
            data = response.json()

Tainted flow: 'url' from os.environ.get (line 552, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The preview/publish submission request is sent to a URL derived from WECHAT_PROXY_URL, carrying an authenticated media_id action under the current access token. A malicious proxy can observe, replay, or alter publishing actions, causing unauthorized publication workflow changes and token compromise.

Content

Scanner excerpt · scripts/wechat_publish.py (reported line 559)May include surrounding context.

python
}

        try:
            response = requests.post(url, json=payload, headers=self._proxy_headers, timeout=30)
            response.raise_for_status()
            data = response.json()

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_KEY_SETUP.md (reported line 30)May include surrounding context.

  1. 复制示例文件:

    bash
    cd C:\Users\jeffl\.claude\skills\content-factory
    copy .env.example .env
    
  2. 编辑 .env 文件:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_KEY_SETUP.md (reported line 212)May include surrounding context.

  1. 复制示例文件:

    bash
    cd C:\Users\jeffl\.claude\skills\content-factory
    copy .env.example .env
    
  2. 编辑 .env 文件:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONFIGURATION.md (reported line 180)May include surrounding context.

  1. 复制示例文件:

    bash
    cd C:\Users\jeffl\.claude\skills\content-factory
    copy .env.example .env
    
  2. 编辑 .env 文件:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONFIGURATION.md (reported line 213)May include surrounding context.

  1. 复制示例文件:

    bash
    cd C:\Users\jeffl\.claude\skills\content-factory
    copy .env.example .env
    
  2. 编辑 .env 文件:

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The example output shows a masked API key value during environment verification, which normalizes displaying secret material in terminal output. Although partially redacted, any disclosure of secret prefixes can aid correlation across logs/screenshots and encourages unsafe operator behavior.

Content

Scanner excerpt · API_KEY_SETUP.md (reported line 147)May include surrounding context.

md
🔑 Environment Configuration Checker
============================================================

📄 Loading environment from: C:\Users\jeffl\.claude\skills\content-factory\.env
   ✅ GLM_API_KEY = sk-1234567...

🔍 Checking required API keys...

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The troubleshooting guidance recommends passing the API key on the command line, which can leak secrets via shell history, process listings, audit logs, and screen captures. This is a well-known insecure secret-handling practice and is especially risky on multi-user systems or monitored environments.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The troubleshooting step instructs users to run type .env, which prints the entire secrets file to the terminal. This can expose API keys and app secrets in shell logs, recordings, remote support sessions, or shared terminals.

Content

Scanner excerpt · API_KEY_SETUP.md (reported line 206)May include surrounding context.

bash
# 检查文件位置
cd C:\Users\jeffl\.claude\skills\content-factory
dir .env

# 查看文件内容
type .env

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The example configuration block contains real-looking API keys and secrets without a strong warning that these must be placeholders only. In documentation for an automation skill that handles publishing and external APIs, this materially increases the risk of secret disclosure and unsafe copy-paste by users.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document includes realistic-looking example secrets for GLM and WeChat in a configuration block, which can be mistaken for real credentials or normalize unsafe secret handling. In a skill that automates publishing and API use, exposing or reusing such values increases the chance of credential leakage, accidental use, or propagation into commits, logs, or screenshots.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONFIGURATION.md (reported line 131)May include surrounding context.

gitignore
   # Environment variables
   .env
   .env.local
   .env.*.local

   # Keep the example file

Credential Access

High
Category
Privilege Escalation
Confidence
85% confidence
Finding

The example checker output shows partially revealed credential values being printed after loading .env. In the context of a content-generation/publishing skill, console output may end up in logs, recordings, or screenshots, creating unnecessary secret exposure and normalizing credential display.

Content

Scanner excerpt · CONFIGURATION.md (reported line 255)May include surrounding context.

md
🔑 Environment Configuration Checker
============================================================

📄 Loading environment from: C:\Users\jeffl\.claude\skills\content-factory\.env
   ✅ GLM_API_KEY = sk-abc123de...
   ✅ WECHAT_APP_ID = wxf9400829...
   ✅ WECHAT_APP_SECRET = a6800143c0...

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises an end-to-end article creation skill centered on researching YouTube content and generating WeChat articles. The supplied code does none of that. Its sole purpose is to read a .env file, populate environment variables, and report whether API keys and WeChat credentials are configured. This is a materially different primary purpose and an undeclared capability unrelated to the described article-writing workflow. While environment setup could theoretically support a larger system, this code chunk itself does not implement the declared behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is centered on content creation and research for WeChat articles, while the actual code performs image compression only. It does not research YouTube, interact with a user about outlines, generate article text, or produce Markdown/HTML. Its primary purpose is materially different from the description, making this a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose centers on content generation from a user-provided title, including external research on YouTube, user confirmation, iterative writing, and formatted article output. The actual code is a utility script for producing and uploading a default cover image to WeChat. Its primary purpose is media asset creation and WeChat material management, not article generation. It also performs undeclared network interaction with WeChat APIs and persists credentials/media identifiers to a config file. These are materially different capabilities and resources from the declared behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared purpose and the actual code behavior. The description promises an end-to-end WeChat article creation workflow involving research, user interaction, content drafting, and Markdown/HTML output. The code instead serves as a demo runner for cover photo generation, calling a separate script with hardcoded example titles/themes/styles and producing PNG files. Its primary purpose is image asset generation, not article generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents an end-to-end article generation skill: research YouTube, confirm topic/outline with the user, write and iterate content, then output Markdown and HTML. The supplied code chunk instead implements a fallback wrapper around dependency scripts and APIs. Its concrete behaviors are subprocess execution of yt-dlp helper scripts for search/captions, invoking a cover-image generation script/API, and invoking a WeChat publish script with fallback to logging/manual publish. Those are adjacent operational utilities, but they are materially different from the declared primary purpose of creating complete articles. The code also adds undeclared capabilities/resources: cover image generation using GLM_API_KEY and WeChat publishing/logging. Because the chunk's behavior is mostly support/orchestration for extraction, media generation, and publishing rather than content creation, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declaration presents a text-content workflow centered on article research, outline confirmation, article drafting, refinement, and Markdown/HTML output. The actual code instead implements image generation for article cover photos via the GLM-Image API, including prompt construction, remote API calls, image download, and resizing. While both relate broadly to WeChat article publishing, the primary purpose and concrete capabilities are materially different, and the code uses an external image-generation service not suggested by the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code's primary purpose is materially different from the declared description. The description promises an end-to-end article creation workflow for WeChat Official Account content, including external research on YouTube, interactive outline confirmation, iterative writing, and Markdown/HTML output. The actual code only tests cover image generation for WeChat articles using a GLM image API and saves image files locally. There is no article generation, no YouTube research, no outline confirmation flow beyond a simple continue prompt, and no Markdown/HTML output. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This code chunk does not implement the declared article-generation workflow. Instead, it performs configuration and secret-loading for a WeChat Official Account by reading app credentials from a local file and exposing a default cover media ID. That is a materially different behavior from researching YouTube videos, confirming outlines with the user, writing content, or generating Markdown/HTML. Because the declared permissions are empty, the credential-file access is also an undeclared resource access. Therefore this chunk is mismatched relative to the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about an article-generation skill: researching high-view YouTube videos, collaborating on topic/outline, writing and iterating content, and producing Markdown/HTML output. The supplied code does none of that. It is an infrastructure component: a Tencent Cloud SCF function that authenticates inbound requests with X-Proxy-Token and proxies a small set of WeChat Official Account API calls through a fixed public IP. Its primary purpose, resources accessed, and trigger model are materially different from the declaration. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.