T01 · Skill Instruction Hijacking
- Location
SKILL.md:1147- Finding
Mandatory Commercial Content Injection Into User Deliverables
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches a WeChat content workflow, but it handles credentials and publishing authority in unsafe, under-scoped ways that require careful review before use.
Do not install this version unless you are comfortable reviewing and fixing its credential handling first. Remove hardcoded WeChat secrets, replace credential checks with non-disclosing status checks, avoid printing .env files or passing secrets on the command line, require an HTTPS allowlisted proxy if proxying is used, and make promotional CTA/reference behavior opt-in. Rotate any WeChat, Tavily, Brave, or GLM credentials if these scripts or checks have already been run in logged environments.
SKILL.md:1147Mandatory Commercial Content Injection Into User Deliverables
scripts/create_default_cover.py:27Hardcoded WeChat Account Credentials in Source Code and Documentation
SKILL.md:149Mandatory Tool Check Prints Complete Search API Keys
scripts/wechat_publish.py:90Unrestricted Proxy Configuration Can Exfiltrate WeChat Credentials and Unpublished Content
scripts/check_env.py:68Environment Checker Discloses Credential Prefixes to Logs
The request target for token retrieval is derived from WECHAT_PROXY_URL, an environment-controlled value, and the request includes highly sensitive app credentials as query parameters. If that proxy URL is pointed to an attacker-controlled host, the script will exfiltrate APPID and APPSECRET and trust the returned access token response, enabling credential theft and account takeover of the WeChat publishing workflow.
}
try:
response = requests.get(TOKEN_URL, params=params, headers=self._proxy_headers, timeout=10)
response.raise_for_status()
data = response.json()
Cover image upload uses an endpoint derived from the environment-controlled proxy base and includes the access token in the URL while transmitting local file contents. If misconfigured or attacker-influenced, the script will upload local media to an untrusted endpoint, leaking data and enabling token theft.
try:
with open(image_path, 'rb') as f:
files = {'media': (image_path.name, f, 'image/png')}
response = requests.post(url, files=files, headers=self._proxy_headers, timeout=60)
response.raise_for_status()
data = response.json()
Content image upload sends local files to a request target ultimately controlled by WECHAT_PROXY_URL, along with the access token in the query string. This creates a direct exfiltration path for article assets and credentials to an attacker-controlled proxy, with little user visibility beyond normal publish behavior.
try:
with open(image_path, 'rb') as f:
files = {'media': (image_path.name, f, 'image/png')}
response = requests.post(url, files=files, headers=self._proxy_headers, timeout=60)
response.raise_for_status()
data = response.json()
The draft creation endpoint is built from an environment-controlled proxy base, so article content, metadata, and the access token embedded in the URL may be sent to an attacker-controlled service. This allows interception or modification of content and abuse of the bearer token for unauthorized WeChat API operations.
json_data = json.dumps(payload, ensure_ascii=False).encode('utf-8')
headers = {'Content-Type': 'application/json; charset=utf-8'}
headers.update(self._proxy_headers)
response = requests.post(url, data=json_data, headers=headers, timeout=30)
response.raise_for_status()
data = response.json()
The preview/publish submission request is sent to a URL derived from WECHAT_PROXY_URL, carrying an authenticated media_id action under the current access token. A malicious proxy can observe, replay, or alter publishing actions, causing unauthorized publication workflow changes and token compromise.
}
try:
response = requests.post(url, json=payload, headers=self._proxy_headers, timeout=30)
response.raise_for_status()
data = response.json()
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
复制示例文件:
cd C:\Users\jeffl\.claude\skills\content-factory
copy .env.example .env
编辑 .env 文件:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
复制示例文件:
cd C:\Users\jeffl\.claude\skills\content-factory
copy .env.example .env
编辑 .env 文件:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
复制示例文件:
cd C:\Users\jeffl\.claude\skills\content-factory
copy .env.example .env
编辑 .env 文件:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
复制示例文件:
cd C:\Users\jeffl\.claude\skills\content-factory
copy .env.example .env
编辑 .env 文件:
The example output shows a masked API key value during environment verification, which normalizes displaying secret material in terminal output. Although partially redacted, any disclosure of secret prefixes can aid correlation across logs/screenshots and encourages unsafe operator behavior.
🔑 Environment Configuration Checker
============================================================
📄 Loading environment from: C:\Users\jeffl\.claude\skills\content-factory\.env
✅ GLM_API_KEY = sk-1234567...
🔍 Checking required API keys...
The troubleshooting guidance recommends passing the API key on the command line, which can leak secrets via shell history, process listings, audit logs, and screen captures. This is a well-known insecure secret-handling practice and is especially risky on multi-user systems or monitored environments.
The troubleshooting step instructs users to run type .env, which prints the entire secrets file to the terminal. This can expose API keys and app secrets in shell logs, recordings, remote support sessions, or shared terminals.
# 检查文件位置
cd C:\Users\jeffl\.claude\skills\content-factory
dir .env
# 查看文件内容
type .env
The example configuration block contains real-looking API keys and secrets without a strong warning that these must be placeholders only. In documentation for an automation skill that handles publishing and external APIs, this materially increases the risk of secret disclosure and unsafe copy-paste by users.
The document includes realistic-looking example secrets for GLM and WeChat in a configuration block, which can be mistaken for real credentials or normalize unsafe secret handling. In a skill that automates publishing and API use, exposing or reusing such values increases the chance of credential leakage, accidental use, or propagation into commits, logs, or screenshots.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Environment variables
.env
.env.local
.env.*.local
# Keep the example file
The example checker output shows partially revealed credential values being printed after loading .env. In the context of a content-generation/publishing skill, console output may end up in logs, recordings, or screenshots, creating unnecessary secret exposure and normalizing credential display.
🔑 Environment Configuration Checker
============================================================
📄 Loading environment from: C:\Users\jeffl\.claude\skills\content-factory\.env
✅ GLM_API_KEY = sk-abc123de...
✅ WECHAT_APP_ID = wxf9400829...
✅ WECHAT_APP_SECRET = a6800143c0...
The declared description promises an end-to-end article creation skill centered on researching YouTube content and generating WeChat articles. The supplied code does none of that. Its sole purpose is to read a .env file, populate environment variables, and report whether API keys and WeChat credentials are configured. This is a materially different primary purpose and an undeclared capability unrelated to the described article-writing workflow. While environment setup could theoretically support a larger system, this code chunk itself does not implement the declared behavior.
The declared purpose is centered on content creation and research for WeChat articles, while the actual code performs image compression only. It does not research YouTube, interact with a user about outlines, generate article text, or produce Markdown/HTML. Its primary purpose is materially different from the description, making this a clear mismatch.
There is a clear description-behavior mismatch. The declared purpose centers on content generation from a user-provided title, including external research on YouTube, user confirmation, iterative writing, and formatted article output. The actual code is a utility script for producing and uploading a default cover image to WeChat. Its primary purpose is media asset creation and WeChat material management, not article generation. It also performs undeclared network interaction with WeChat APIs and persists credentials/media identifiers to a config file. These are materially different capabilities and resources from the declared behavior.
There is a clear mismatch between the declared purpose and the actual code behavior. The description promises an end-to-end WeChat article creation workflow involving research, user interaction, content drafting, and Markdown/HTML output. The code instead serves as a demo runner for cover photo generation, calling a separate script with hardcoded example titles/themes/styles and producing PNG files. Its primary purpose is image asset generation, not article generation.
The declared description presents an end-to-end article generation skill: research YouTube, confirm topic/outline with the user, write and iterate content, then output Markdown and HTML. The supplied code chunk instead implements a fallback wrapper around dependency scripts and APIs. Its concrete behaviors are subprocess execution of yt-dlp helper scripts for search/captions, invoking a cover-image generation script/API, and invoking a WeChat publish script with fallback to logging/manual publish. Those are adjacent operational utilities, but they are materially different from the declared primary purpose of creating complete articles. The code also adds undeclared capabilities/resources: cover image generation using GLM_API_KEY and WeChat publishing/logging. Because the chunk's behavior is mostly support/orchestration for extraction, media generation, and publishing rather than content creation, the description does not accurately represent this code chunk.
There is a clear description-behavior mismatch. The declaration presents a text-content workflow centered on article research, outline confirmation, article drafting, refinement, and Markdown/HTML output. The actual code instead implements image generation for article cover photos via the GLM-Image API, including prompt construction, remote API calls, image download, and resizing. While both relate broadly to WeChat article publishing, the primary purpose and concrete capabilities are materially different, and the code uses an external image-generation service not suggested by the declared description.
The code's primary purpose is materially different from the declared description. The description promises an end-to-end article creation workflow for WeChat Official Account content, including external research on YouTube, interactive outline confirmation, iterative writing, and Markdown/HTML output. The actual code only tests cover image generation for WeChat articles using a GLM image API and saves image files locally. There is no article generation, no YouTube research, no outline confirmation flow beyond a simple continue prompt, and no Markdown/HTML output. This is a clear description-behavior mismatch.
This code chunk does not implement the declared article-generation workflow. Instead, it performs configuration and secret-loading for a WeChat Official Account by reading app credentials from a local file and exposing a default cover media ID. That is a materially different behavior from researching YouTube videos, confirming outlines with the user, writing content, or generating Markdown/HTML. Because the declared permissions are empty, the credential-file access is also an undeclared resource access. Therefore this chunk is mismatched relative to the stated purpose.
The declared description is about an article-generation skill: researching high-view YouTube videos, collaborating on topic/outline, writing and iterating content, and producing Markdown/HTML output. The supplied code does none of that. It is an infrastructure component: a Tencent Cloud SCF function that authenticates inbound requests with X-Proxy-Token and proxies a small set of WeChat Official Account API calls through a fixed public IP. Its primary purpose, resources accessed, and trigger model are materially different from the declaration. This is a clear description-behavior mismatch.
No suspicious patterns detected.