Back to skill

Security audit

content-factory

Security checks for vulnerabilities and agentic risk

Overview

The skill’s article-writing purpose is coherent, but it asks the agent to read and print local API credentials and includes real-looking WeChat credential examples, so it should be reviewed carefully before installation.

Install only if you are comfortable auditing and modifying the credential-handling steps. Before use, remove or redact hardcoded credential examples, do not run commands that print API keys, verify any local scripts before execution, and require a manual confirmation step before any WeChat publishing action.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
API_KEY_SETUP.md:55

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
CONFIGURATION.md:100

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/create_default_cover.py:238

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/generate_cover_photo.py:433