T01 · Skill Instruction Hijacking
- Location
SKILL.md:1146- Finding
Mandatory promotional content and suppression of source references
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real content-creation skill, but it handles publishing credentials and persistent output in ways that could leak secrets or submit content without adequate safeguards.
Review this skill carefully before installing. Do not run the credential-check commands as written because they print secrets. Remove or rotate the exposed WeChat secret, require HTTPS and an allowlisted proxy host, disable automatic WeChat submission until final content is explicitly approved, avoid shared memory for untrusted research unless isolated, and pin dependencies in a controlled environment.
SKILL.md:1146Mandatory promotional content and suppression of source references
scripts/create_default_cover.py:27Hardcoded WeChat credentials persisted into executable source code
scripts/wechat_proxy_scf/wechat_proxy_server.py:10Plaintext proxy can expose WeChat credentials, tokens, unpublished articles, and images
SKILL.md:149Mandatory checks print complete API keys and access global credential files
SKILL.md:301Untrusted research is written into persistent shared Agent memory
SKILL.md:126Unpinned third-party package installation instruction
The script allows WECHAT_PROXY_URL from the environment to replace the trusted WeChat API base URL, and then sends app credentials to TOKEN_URL. If an attacker can influence the environment or packaged skill configuration, they can redirect authentication traffic to an attacker-controlled endpoint and capture APPID/APPSECRET and subsequent access tokens.
}
try:
response = requests.get(TOKEN_URL, params=params, headers=self._proxy_headers, timeout=10)
response.raise_for_status()
data = response.json()
Cover image upload sends local file contents plus access_token to an endpoint that may be controlled through WECHAT_PROXY_URL. If redirected, this can leak local files selected for upload and expose the account token to an untrusted service.
try:
with open(image_path, 'rb') as f:
files = {'media': (image_path.name, f, 'image/png')}
response = requests.post(url, files=files, headers=self._proxy_headers, timeout=60)
response.raise_for_status()
data = response.json()
Content image upload transmits local image data to a URL influenced by environment configuration, creating a straightforward exfiltration path for local files and access tokens. In a skill context, this is especially sensitive because article assets may be user-provided or locally generated content not intended for third parties.
try:
with open(image_path, 'rb') as f:
files = {'media': (image_path.name, f, 'image/png')}
response = requests.post(url, files=files, headers=self._proxy_headers, timeout=60)
response.raise_for_status()
data = response.json()
The request URL used for draft creation is derived from the environment-controlled proxy base, so article content and bearer access_token can be transmitted to an arbitrary endpoint. This enables exfiltration of generated content and account-scoped API credentials if the proxy setting is malicious or misconfigured.
json_data = json.dumps(payload, ensure_ascii=False).encode('utf-8')
headers = {'Content-Type': 'application/json; charset=utf-8'}
headers.update(self._proxy_headers)
response = requests.post(url, data=json_data, headers=headers, timeout=30)
response.raise_for_status()
data = response.json()
Preview submission posts the media_id and access_token to a URL built from environment-controlled proxy configuration. A hostile proxy endpoint could collect tokens, metadata, and operational information or manipulate publication workflow responses.
}
try:
response = requests.post(url, json=payload, headers=self._proxy_headers, timeout=30)
response.raise_for_status()
data = response.json()
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
复制示例文件:
cd C:\Users\jeffl\.claude\skills\content-factory
copy .env.example .env
编辑 .env 文件:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
复制示例文件:
cd C:\Users\jeffl\.claude\skills\content-factory
copy .env.example .env
编辑 .env 文件:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
复制示例文件:
cd C:\Users\jeffl\.claude\skills\content-factory
copy .env.example .env
编辑 .env 文件:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
复制示例文件:
cd C:\Users\jeffl\.claude\skills\content-factory
copy .env.example .env
编辑 .env 文件:
This troubleshooting section advises users to pass the API key directly with --api-key, which materially increases the chance of credential exposure through shell history, process inspection, audit logs, or screenshots. In a content-generation skill that relies on external API credentials, leaked keys could enable unauthorized API usage and billing abuse.
**解决方案**:
1. 检查 .env 文件是否存在且包含正确的 API Key
2. 检查环境变量是否设置:`echo $env:GLM_API_KEY` (PowerShell)
3. 尝试使用 `--api-key` 参数直接传递:
```bash
The documentation includes values that appear to be real API credentials in the '.env' example block, directly contradicting the stated guidance against hardcoding secrets. If these are valid or were ever valid, anyone reading the file can reuse them to access third-party services, publish content, or abuse the associated accounts.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Environment variables
.env
.env.local
.env.*.local
# Keep the example file
There is a clear description-behavior mismatch. The declared purpose describes an end-user content creation skill centered on generating WeChat viral articles using YouTube research and iterative writing. The actual code does none of that. Instead, it reads a .env file, populates environment variables, checks whether required and optional API keys are configured, and prints setup guidance. While WeChat credentials are mentioned, that is only for configuration checking and does not implement article creation, research, or publishing. This is a materially different primary purpose, so it should be flagged as a mismatch.
There is a clear mismatch between the declared purpose and the actual code. The description claims a content-generation workflow for WeChat articles involving research, interaction, writing, and dual-format output. The code does none of that. Instead, it performs local image processing: opening an image, handling transparency, converting to JPEG, compressing for upload constraints, and printing size statistics. This is a materially different primary purpose and introduces an undeclared capability related to file/image manipulation.
This is a clear mismatch. The declared description is about generating complete viral WeChat articles from a title, including external research, user confirmation, iterative writing, and formatted article output. The actual code does none of that. Its primary purpose is asset management for WeChat publishing: generate a simple JPEG cover image, call WeChat APIs with embedded APPID/APPSECRET, upload the image, and save configuration data. While cover-image handling could be a supporting feature in a broader publishing system, this code chunk’s behavior is materially different from the declared primary function and introduces undeclared capabilities involving network access to WeChat and credential/config file handling.
There is a clear material mismatch between the declared purpose and the actual code. The description claims an end-to-end article generation workflow for WeChat articles, including research, user confirmation, drafting, and Markdown/HTML export. The code instead serves as an example driver for generating cover photo images using predefined prompts and a GLM image API via a subprocess call. Its primary purpose is image asset generation, not article research or writing.
The declared description promises an end-to-end content-generation skill: research YouTube, confirm topic/outline with the user, write and refine a professional article, and produce Markdown/HTML outputs. The supplied code chunk instead is a utility wrapper around external scripts and APIs. Its concrete behavior is limited to invoking subprocesses for YouTube search/captions, cover generation, and WeChat publishing, with fallback handling and logging. There is no code for article drafting, topic confirmation, iterative writing, or rendering article bodies into Markdown/HTML. This is therefore a material description-behavior mismatch: the code's primary purpose is fallback orchestration for dependencies, not complete article creation.
There is a strong mismatch between the declared purpose and the actual code. The description promises an end-to-end article-generation workflow centered on research and text production for WeChat Official Account posts. In contrast, the code only handles visual asset generation for a cover image. Its primary purpose is materially different: image creation via a third-party API plus local file processing. The external resource usage is also inconsistent with the description, since the code contacts the GLM image generation endpoint rather than researching YouTube content. This is not a minor supporting detail of article creation; it is a separate capability with a different output type and workflow.
The declared description is about end-to-end article creation for WeChat Official Accounts, including YouTube research, user confirmation, iterative writing, and Markdown/HTML output. The supplied code does something materially different: it is a manual test harness for cover image generation. It checks for requests/Pillow, requires GLM_API_KEY, asks whether to continue, invokes scripts/generate_cover_photo.py with hardcoded test cases, stores PNG outputs, and reports image sizes. This is not a supporting implementation detail of article writing; it is a separate image-generation/testing function with different inputs, outputs, and external resource usage. Therefore the description does not accurately represent the code chunk.
The supplied code chunk does not implement article generation, YouTube research, user outline confirmation, self-iteration, or Markdown/HTML output. Instead, it is a configuration module for WeChat publishing that reads sensitive credentials from a local file and exposes app authentication settings and a default cover media ID. This is a materially different primary purpose from the declared article-creation behavior, so the description does not accurately represent the code shown.
The declared description says this skill generates WeChat viral articles by researching YouTube content and producing polished article outputs in Markdown and HTML. The supplied code does none of that. Instead, it is an infrastructure component: a secured proxy service for forwarding requests to selected WeChat Official Account API endpoints through a fixed Tencent Cloud egress IP. This is a materially different primary purpose and includes undeclared network-proxy capabilities. Therefore the description does not accurately represent the code's actual behavior.
The declared description is about researching YouTube content and generating polished WeChat articles with Markdown/HTML output. The supplied code does none of that: it contains no YouTube research, no user topic/outline confirmation flow, no article writing logic, no self-iteration, and no Markdown/HTML rendering. Instead, its primary purpose is infrastructure: an authenticated proxy service that relays selected WeChat API calls through a fixed-IP VPS. This is a materially different purpose and introduces undeclared network/API proxy capabilities unrelated to the declared content-creation behavior.
The declared description says the skill creates complete WeChat articles from a title, including external research, iterative writing, and output in Markdown and HTML. The supplied code does none of that. Instead, it takes an already-created HTML file and optional cover image, uploads images to WeChat, converts HTML styling for WeChat compatibility, creates a draft via WeChat APIs, and submits a preview/publish request. This is a materially different primary purpose: publication of existing content rather than generation of new content. It also performs credentialed WeChat API access and publishing actions that are not represented in the declared description.
The declared description describes a content-generation skill for producing WeChat articles from a title, including research, interactive outline confirmation, iterative writing, and formatted article output. The supplied code does none of that. It is a standalone CLI script for a different primary purpose: fetching YouTube subtitles and optionally transcribing audio with Whisper. It accepts a YouTube URL, interacts with yt-dlp and whisper, writes subtitle/audio/transcript files locally, and has no logic for article drafting, user interaction, topic confirmation, or Markdown/HTML generation. This is a clear material mismatch in both purpose and capabilities.
The declared description presents a full article-generation workflow: researching YouTube content, interacting with the user to confirm structure, producing professional WeChat article content, and exporting in Markdown and HTML. The supplied code chunk does only one narrow supporting task: it invokes yt-dlp to search YouTube and serialize video metadata to JSON/JSONL. There is no article drafting, user confirmation flow, content generation, iterative refinement, or Markdown/HTML export in this code. This is therefore a material description-behavior mismatch in primary purpose and implemented capabilities.
No suspicious patterns detected.