Back to skill

Security audit

jeffli-content-factory

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real content-creation skill, but it handles publishing credentials and persistent output in ways that could leak secrets or submit content without adequate safeguards.

Review this skill carefully before installing. Do not run the credential-check commands as written because they print secrets. Remove or rotate the exposed WeChat secret, require HTTPS and an allowlisted proxy host, disable automatic WeChat submission until final content is explicitly approved, avoid shared memory for untrusted research unless isolated, and pin dependencies in a controlled environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:1146
Finding

Mandatory promotional content and suppression of source references

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/create_default_cover.py:27
Finding

Hardcoded WeChat credentials persisted into executable source code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/wechat_proxy_scf/wechat_proxy_server.py:10
Finding

Plaintext proxy can expose WeChat credentials, tokens, unpublished articles, and images

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:149
Finding

Mandatory checks print complete API keys and access global credential files

Content
View full analysis
10 else f" OK {key} = {value}" ) ``` ### Technical Analysis Checking whether a key exists does not require revealing its value. The Skill nevertheless prints complete Tavily and Brave keys as part of a mandatory workflow. These values may be retained in terminal history, Agent transcripts, CI logs, orchestration logs, or monitoring systems. The publisher imports the bundled `wechat_config.py` successfully and therefore reads `/root/.openclaw/credentials/wechat.json` whenever present. This creates an implicit dependency on a global credential store and accesses credentials outside the project directory without an explicit user selection. Printing the first ten characters of secrets is also unnecessary. Prefixes ...[truncated 1260 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:301
Finding

Untrusted research is written into persistent shared Agent memory

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:126
Finding

Unpinned third-party package installation instruction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (193)

Tainted flow: 'TOKEN_URL' from os.environ.get (line 96, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The script allows WECHAT_PROXY_URL from the environment to replace the trusted WeChat API base URL, and then sends app credentials to TOKEN_URL. If an attacker can influence the environment or packaged skill configuration, they can redirect authentication traffic to an attacker-controlled endpoint and capture APPID/APPSECRET and subsequent access tokens.

Content

Scanner excerpt · scripts/wechat_publish.py (reported line 156)May include surrounding context.

python
}

        try:
            response = requests.get(TOKEN_URL, params=params, headers=self._proxy_headers, timeout=10)
            response.raise_for_status()
            data = response.json()

Tainted flow: 'url' from os.environ.get (line 552, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

Cover image upload sends local file contents plus access_token to an endpoint that may be controlled through WECHAT_PROXY_URL. If redirected, this can leak local files selected for upload and expose the account token to an untrusted service.

Content

Scanner excerpt · scripts/wechat_publish.py (reported line 205)May include surrounding context.

python
try:
            with open(image_path, 'rb') as f:
                files = {'media': (image_path.name, f, 'image/png')}
                response = requests.post(url, files=files, headers=self._proxy_headers, timeout=60)
                response.raise_for_status()
                data = response.json()

Tainted flow: 'url' from os.environ.get (line 552, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

Content image upload transmits local image data to a URL influenced by environment configuration, creating a straightforward exfiltration path for local files and access tokens. In a skill context, this is especially sensitive because article assets may be user-provided or locally generated content not intended for third parties.

Content

Scanner excerpt · scripts/wechat_publish.py (reported line 253)May include surrounding context.

python
try:
            with open(image_path, 'rb') as f:
                files = {'media': (image_path.name, f, 'image/png')}
                response = requests.post(url, files=files, headers=self._proxy_headers, timeout=60)
                response.raise_for_status()
                data = response.json()

Tainted flow: 'url' from os.environ.get (line 552, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The request URL used for draft creation is derived from the environment-controlled proxy base, so article content and bearer access_token can be transmitted to an arbitrary endpoint. This enables exfiltration of generated content and account-scoped API credentials if the proxy setting is malicious or misconfigured.

Content

Scanner excerpt · scripts/wechat_publish.py (reported line 518)May include surrounding context.

python
json_data = json.dumps(payload, ensure_ascii=False).encode('utf-8')
            headers = {'Content-Type': 'application/json; charset=utf-8'}
            headers.update(self._proxy_headers)
            response = requests.post(url, data=json_data, headers=headers, timeout=30)
            response.raise_for_status()
            data = response.json()

Tainted flow: 'url' from os.environ.get (line 552, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

Preview submission posts the media_id and access_token to a URL built from environment-controlled proxy configuration. A hostile proxy endpoint could collect tokens, metadata, and operational information or manipulate publication workflow responses.

Content

Scanner excerpt · scripts/wechat_publish.py (reported line 559)May include surrounding context.

python
}

        try:
            response = requests.post(url, json=payload, headers=self._proxy_headers, timeout=30)
            response.raise_for_status()
            data = response.json()

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_KEY_SETUP.md (reported line 30)May include surrounding context.

  1. 复制示例文件:

    bash
    cd C:\Users\jeffl\.claude\skills\content-factory
    copy .env.example .env
    
  2. 编辑 .env 文件:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_KEY_SETUP.md (reported line 212)May include surrounding context.

  1. 复制示例文件:

    bash
    cd C:\Users\jeffl\.claude\skills\content-factory
    copy .env.example .env
    
  2. 编辑 .env 文件:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONFIGURATION.md (reported line 180)May include surrounding context.

  1. 复制示例文件:

    bash
    cd C:\Users\jeffl\.claude\skills\content-factory
    copy .env.example .env
    
  2. 编辑 .env 文件:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONFIGURATION.md (reported line 213)May include surrounding context.

  1. 复制示例文件:

    bash
    cd C:\Users\jeffl\.claude\skills\content-factory
    copy .env.example .env
    
  2. 编辑 .env 文件:

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This troubleshooting section advises users to pass the API key directly with --api-key, which materially increases the chance of credential exposure through shell history, process inspection, audit logs, or screenshots. In a content-generation skill that relies on external API credentials, leaked keys could enable unauthorized API usage and billing abuse.

Content

Scanner excerpt · API_KEY_SETUP.md (reported line 184)May include surrounding context.

text

**解决方案**:
1. 检查 .env 文件是否存在且包含正确的 API Key
2. 检查环境变量是否设置:`echo $env:GLM_API_KEY` (PowerShell)
3. 尝试使用 `--api-key` 参数直接传递:
   ```bash

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation includes values that appear to be real API credentials in the '.env' example block, directly contradicting the stated guidance against hardcoding secrets. If these are valid or were ever valid, anyone reading the file can reuse them to access third-party services, publish content, or abuse the associated accounts.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONFIGURATION.md (reported line 131)May include surrounding context.

gitignore
   # Environment variables
   .env
   .env.local
   .env.*.local

   # Keep the example file

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose describes an end-user content creation skill centered on generating WeChat viral articles using YouTube research and iterative writing. The actual code does none of that. Instead, it reads a .env file, populates environment variables, checks whether required and optional API keys are configured, and prints setup guidance. While WeChat credentials are mentioned, that is only for configuration checking and does not implement article creation, research, or publishing. This is a materially different primary purpose, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared purpose and the actual code. The description claims a content-generation workflow for WeChat articles involving research, interaction, writing, and dual-format output. The code does none of that. Instead, it performs local image processing: opening an image, handling transparency, converting to JPEG, compressing for upload constraints, and printing size statistics. This is a materially different primary purpose and introduces an undeclared capability related to file/image manipulation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is a clear mismatch. The declared description is about generating complete viral WeChat articles from a title, including external research, user confirmation, iterative writing, and formatted article output. The actual code does none of that. Its primary purpose is asset management for WeChat publishing: generate a simple JPEG cover image, call WeChat APIs with embedded APPID/APPSECRET, upload the image, and save configuration data. While cover-image handling could be a supporting feature in a broader publishing system, this code chunk’s behavior is materially different from the declared primary function and introduces undeclared capabilities involving network access to WeChat and credential/config file handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear material mismatch between the declared purpose and the actual code. The description claims an end-to-end article generation workflow for WeChat articles, including research, user confirmation, drafting, and Markdown/HTML export. The code instead serves as an example driver for generating cover photo images using predefined prompts and a GLM image API via a subprocess call. Its primary purpose is image asset generation, not article research or writing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises an end-to-end content-generation skill: research YouTube, confirm topic/outline with the user, write and refine a professional article, and produce Markdown/HTML outputs. The supplied code chunk instead is a utility wrapper around external scripts and APIs. Its concrete behavior is limited to invoking subprocesses for YouTube search/captions, cover generation, and WeChat publishing, with fallback handling and logging. There is no code for article drafting, topic confirmation, iterative writing, or rendering article bodies into Markdown/HTML. This is therefore a material description-behavior mismatch: the code's primary purpose is fallback orchestration for dependencies, not complete article creation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a strong mismatch between the declared purpose and the actual code. The description promises an end-to-end article-generation workflow centered on research and text production for WeChat Official Account posts. In contrast, the code only handles visual asset generation for a cover image. Its primary purpose is materially different: image creation via a third-party API plus local file processing. The external resource usage is also inconsistent with the description, since the code contacts the GLM image generation endpoint rather than researching YouTube content. This is not a minor supporting detail of article creation; it is a separate capability with a different output type and workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about end-to-end article creation for WeChat Official Accounts, including YouTube research, user confirmation, iterative writing, and Markdown/HTML output. The supplied code does something materially different: it is a manual test harness for cover image generation. It checks for requests/Pillow, requires GLM_API_KEY, asks whether to continue, invokes scripts/generate_cover_photo.py with hardcoded test cases, stores PNG outputs, and reports image sizes. This is not a supporting implementation detail of article writing; it is a separate image-generation/testing function with different inputs, outputs, and external resource usage. Therefore the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code chunk does not implement article generation, YouTube research, user outline confirmation, self-iteration, or Markdown/HTML output. Instead, it is a configuration module for WeChat publishing that reads sensitive credentials from a local file and exposes app authentication settings and a default cover media ID. This is a materially different primary purpose from the declared article-creation behavior, so the description does not accurately represent the code shown.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill generates WeChat viral articles by researching YouTube content and producing polished article outputs in Markdown and HTML. The supplied code does none of that. Instead, it is an infrastructure component: a secured proxy service for forwarding requests to selected WeChat Official Account API endpoints through a fixed Tencent Cloud egress IP. This is a materially different primary purpose and includes undeclared network-proxy capabilities. Therefore the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about researching YouTube content and generating polished WeChat articles with Markdown/HTML output. The supplied code does none of that: it contains no YouTube research, no user topic/outline confirmation flow, no article writing logic, no self-iteration, and no Markdown/HTML rendering. Instead, its primary purpose is infrastructure: an authenticated proxy service that relays selected WeChat API calls through a fixed-IP VPS. This is a materially different purpose and introduces undeclared network/API proxy capabilities unrelated to the declared content-creation behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says the skill creates complete WeChat articles from a title, including external research, iterative writing, and output in Markdown and HTML. The supplied code does none of that. Instead, it takes an already-created HTML file and optional cover image, uploads images to WeChat, converts HTML styling for WeChat compatibility, creates a draft via WeChat APIs, and submits a preview/publish request. This is a materially different primary purpose: publication of existing content rather than generation of new content. It also performs credentialed WeChat API access and publishing actions that are not represented in the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a content-generation skill for producing WeChat articles from a title, including research, interactive outline confirmation, iterative writing, and formatted article output. The supplied code does none of that. It is a standalone CLI script for a different primary purpose: fetching YouTube subtitles and optionally transcribing audio with Whisper. It accepts a YouTube URL, interacts with yt-dlp and whisper, writes subtitle/audio/transcript files locally, and has no logic for article drafting, user interaction, topic confirmation, or Markdown/HTML generation. This is a clear material mismatch in both purpose and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a full article-generation workflow: researching YouTube content, interacting with the user to confirm structure, producing professional WeChat article content, and exporting in Markdown and HTML. The supplied code chunk does only one narrow supporting task: it invokes yt-dlp to search YouTube and serialize video metadata to JSON/JSONL. There is no article drafting, user confirmation flow, content generation, iterative refinement, or Markdown/HTML export in this code. This is therefore a material description-behavior mismatch in primary purpose and implemented capabilities.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.