Back to skill

Security audit

WeChat朋友圈营销

Security checks for vulnerabilities and agentic risk

Overview

This WeChat marketing skill has a coherent purpose, but it exposes an unauthenticated public callback workflow that can store arbitrary data and drive unsafe downloads.

Review before installing. Use only with non-sensitive campaign content unless you are comfortable sending it to KIE or Seedream, do not expose the callback server publicly without authentication and size limits, and avoid using the QR/contact features for private personal data unless you intend that data to appear in generated assets.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/kie-callback-server.py:8
Finding

Unauthenticated Public Callback Endpoint Permits Arbitrary Data Persistence

Content
View full analysis
Remediation
View remediation
` and return `404` or `403` for all other POST paths. 4. Enforce a conservative maximum body size before calling `read`, such as 256 KB, and reject missing, invalid, negative, or excessive `Content-Length` values with HTTP `413`. 5. Require the expected JSON content type and validate the parsed callback against a strict schema. 6. Do not persist all incoming headers. Explicitly retain only non-sensitive fields required for troubleshooting. 7. Use collision-resistant filenames containing a task ID plus a random UUID, and create files atomically with exclusive creation semantics. 8. Configure file permissions so only the service account can read callback data. 9. Add expiration and storage quotas for callback records. 10. Place rate limiting and request-size controls in front of the tunnel. 11. Replace the single-threaded server or configure strict read timeouts to mitigate slow-request denial of service. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/kie-wait-download.py:13
Finding

Forged Callback Results Enable Server-Side Request Forgery and Unrestricted Downloads

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared scope promises professional copy generation and broader WeChat content support, but the implementation reportedly only performs limited image/poster functions. This is primarily a trust and governance vulnerability: reviewers may approve or invoke the skill for one purpose while it behaves as a different tool, undermining permission scoping and user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared scope promises professional copy generation and broader WeChat content support, but the implementation reportedly only performs limited image/poster functions. This is primarily a trust and governance vulnerability: reviewers may approve or invoke the skill for one purpose while it behaves as a different tool, undermining permission scoping and user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared scope promises professional copy generation and broader WeChat content support, but the implementation reportedly only performs limited image/poster functions. This is primarily a trust and governance vulnerability: reviewers may approve or invoke the skill for one purpose while it behaves as a different tool, undermining permission scoping and user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared scope promises professional copy generation and broader WeChat content support, but the implementation reportedly only performs limited image/poster functions. This is primarily a trust and governance vulnerability: reviewers may approve or invoke the skill for one purpose while it behaves as a different tool, undermining permission scoping and user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared scope promises professional copy generation and broader WeChat content support, but the implementation reportedly only performs limited image/poster functions. This is primarily a trust and governance vulnerability: reviewers may approve or invoke the skill for one purpose while it behaves as a different tool, undermining permission scoping and user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared scope promises professional copy generation and broader WeChat content support, but the implementation reportedly only performs limited image/poster functions. This is primarily a trust and governance vulnerability: reviewers may approve or invoke the skill for one purpose while it behaves as a different tool, undermining permission scoping and user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script binds an HTTP server to 0.0.0.0 on a configurable port, exposing an inbound listener to any reachable host. For a marketing-copy skill, there is no obvious legitimate reason to accept unsolicited network traffic, so the listener materially increases exposure to probing, abuse, and unauthorized data submission.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file implements a standalone HTTP callback server that accepts arbitrary POST requests and persists their contents to disk, which is unrelated to the stated purpose of generating WeChat marketing copy. In the context of a content-generation skill, this creates an unnecessary data-ingestion surface that could collect sensitive tokens, personal data, or internal webhook payloads and expands the attack surface without a clear product need.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool or permission scope, yet the specification instructs use of shell commands, filesystem reads/writes, environment-dependent paths, and network-facing operations. This creates an over-privileged skill surface where a caller may invoke powerful behaviors without clear sandboxing or user awareness, increasing the risk of arbitrary file access, outbound requests, and process execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Broad trigger phrases such as common everyday requests can cause the skill to activate unintentionally in contexts where the user did not mean to invoke it. Because this skill can write files and initiate external tooling, accidental invocation increases the chance of unintended data collection, file creation, or network activity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions state that outputs must follow Chinese expression habits and WeChat platform tone, effectively forcing Chinese-language output. Because the file does not offer a language choice or explicitly justify this as a region-locked skill policy, it conflicts with the stated language/locale policy criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly collects and may display personal contact information and QR codes, but it does not present a clear privacy warning or consent mechanism before doing so. In context, this is more dangerous because the data is intended for publication in marketing assets and may also be written to local files, increasing the risk of accidental exposure of phone numbers or personal WeChat identifiers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase When user answers Q4 (是否需要二维码) embeds a Chinese-only prompt reference in otherwise English documentation, implying a fixed language experience. Under the policy, language constraints should either offer user choice or be clearly documented as region-specific and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file includes a natural-language instruction that requires Chinese punctuation, and the surrounding template content is entirely structured for Chinese copy generation. Because the file does not offer any user opt-in or alternative locale/language handling, it effectively imposes a specific language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions require exact reproduction of Chinese copy and present all operational guidance in Chinese, effectively forcing a specific language for the generated output. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific; this file does not state such an opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CTA logic conflicts between 'copy.md CTA line' and generated QR/contact-specific substitutions such as '扫码咨询' or direct contact info. In practice, an agent may ignore source copy, inject different calls to action, or mishandle contact disclosure, leading to inconsistent user-facing output and possible unauthorized publication of contact details.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file first requires all image text to match copy.md verbatim and explicitly forbids adding or rewriting content, but the Zone 4 section later allows adding expanded descriptions. This ambiguity can cause downstream agents to fabricate marketing claims or alter regulated content while still appearing compliant, which is risky in a content-generation workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The handler stores full request headers and parsed body content into summary files, and also writes the raw body to disk. This can capture authorization headers, cookies, personal data, or third-party callback secrets, creating unnecessary local sensitive-data retention that is unrelated to the skill's advertised functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Incoming POST data is silently written to disk, including potentially sensitive callback content, without any visible disclosure, consent, or operator safeguards. In a skill presented as a WeChat content generator, this mismatch makes the behavior more dangerous because users and reviewers would not reasonably expect hidden persistence of arbitrary inbound data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/kie-create-task.py (reported line 7)May include surrounding context.

python
import urllib.request
from pathlib import Path

ENDPOINT = "https://api.kie.ai/api/v1/jobs/createTask"


def load_config():

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code accesses a sensitive credential file and uses the API key to make an outbound HTTP request, but there is no confirmation prompt, visible user-facing log, or explanatory comment/docstring disclosing that behavior. For a standalone code file, this matches the missing-warning criterion for sensitive credential access and network transmission.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script accepts a caller-supplied callback URL and forwards it directly to the external KIE API without validation or restriction. This creates an SSRF-style webhook abuse surface where an attacker can cause job-completion callbacks to be sent to arbitrary external or internal endpoints, which exceeds the stated marketing-content purpose and could be used for network probing, unauthorized outbound requests, or data disclosure through callback metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script takes a caller-specified output path and downloads remote content from a URL obtained from callback data, then writes that content directly to disk without validating the destination path or constraining the source URL. In an agent/skill context, this can enable arbitrary file overwrite within the agent's permissions and SSRF-style access to internal resources if an attacker can influence the callback file contents or task result URL.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/kie-wait-download.py (reported line 34)May include surrounding context.

python
return
    except Exception:
        pass
    subprocess.run(['curl', '-L', url, '-o', str(output_path)], check=True)


def main():

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script transmits user-provided marketing content, pricing, and promotional details to a third-party image-generation API, but it provides no explicit notice, consent step, or data-classification guardrails before doing so. In a marketing skill, users may include business-sensitive campaign plans, unpublished offers, or personal contact details in titles and selling points, creating a real confidentiality and compliance risk if sent externally without warning.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.