Back to skill

Security audit

WeChat Post with GPT Image-2

Security checks for vulnerabilities and agentic risk

Overview

The skill has a plausible WeChat marketing purpose, but it includes an unauthenticated public callback server and unvalidated URL downloads that require careful review before use.

Review before installing or using. Avoid exposing the callback server publicly; prefer a polling-only flow or bind callbacks to localhost with authentication. Assume prompts, product details, phone numbers, and image URLs may be sent to KIE or Seedream, and use a limited API key and a dedicated output directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/kie-callback-server.py:8
Finding

Unauthenticated Public Callback Server Allows Forged Payload Storage and Denial of Service

Content
View full analysis
Remediation
View remediation
MAX_BODY_SIZE: return self._reply(413, {"ok": False, "error": "payload_too_large"}) ``` 6. Apply socket read timeouts to reduce slow-request denial-of-service exposure. 7. Use UUIDs or nanosecond timestamps for filenames to prevent collisions. 8. Store only necessary headers and redact credentials or tokens. 9. Create files with restrictive permissions and run the service under a dedicated, unprivileged account. 10. Place the service behind a reverse proxy that enforces TLS, rate limits, request-size limits, and source restrictions. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/kie-wait-download.py:13
Finding

Forged Callback Results Can Trigger Unrestricted URL Retrieval

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:7
Finding

Unpinned npx Publishing Command Can Execute Unreviewed Registry Code

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The Chinese description similarly overstates supported WeChat/公众号 and copywriting capabilities while understating reliance on external image-generation APIs and local credentials. In context, this makes the skill more dangerous because users may provide lecturer, pricing, and contact information expecting local formatting work, not external transmission and hidden operational behaviors.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The Chinese description similarly overstates supported WeChat/公众号 and copywriting capabilities while understating reliance on external image-generation APIs and local credentials. In context, this makes the skill more dangerous because users may provide lecturer, pricing, and contact information expecting local formatting work, not external transmission and hidden operational behaviors.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The Chinese description similarly overstates supported WeChat/公众号 and copywriting capabilities while understating reliance on external image-generation APIs and local credentials. In context, this makes the skill more dangerous because users may provide lecturer, pricing, and contact information expecting local formatting work, not external transmission and hidden operational behaviors.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The Chinese description similarly overstates supported WeChat/公众号 and copywriting capabilities while understating reliance on external image-generation APIs and local credentials. In context, this makes the skill more dangerous because users may provide lecturer, pricing, and contact information expecting local formatting work, not external transmission and hidden operational behaviors.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The Chinese description similarly overstates supported WeChat/公众号 and copywriting capabilities while understating reliance on external image-generation APIs and local credentials. In context, this makes the skill more dangerous because users may provide lecturer, pricing, and contact information expecting local formatting work, not external transmission and hidden operational behaviors.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The Chinese description similarly overstates supported WeChat/公众号 and copywriting capabilities while understating reliance on external image-generation APIs and local credentials. In context, this makes the skill more dangerous because users may provide lecturer, pricing, and contact information expecting local formatting work, not external transmission and hidden operational behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates external KIE API usage and even suggests exposing a callback endpoint, but does not warn users that prompts, marketing content, and potentially contact data may be sent to third-party services or received over a webhook. This is particularly dangerous because the workflow may include pricing, lecturer info, phone numbers, and QR-related assets that users may not expect to leave the local environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements an unauthenticated HTTP callback server that listens on all interfaces and stores arbitrary POST bodies and request headers to disk. That capability is unrelated to a WeChat marketing/copywriting skill, so in this context it creates unnecessary attack surface and a data collection channel that could receive sensitive or attacker-controlled content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill exposes a persistent network listener via HTTPServer on 0.0.0.0:8787 without any authentication, authorization, or transport protection. For a marketing-content skill, this is unjustified and increases the chance of abuse for unsolicited data ingress, probing, or use as an internal callback sink in environments where the agent has broader network reach.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill directs use of filesystem, shell, environment-backed credentials, and network operations but declares no explicit tool scope or allowed-tools policy. That creates unnecessary ambiguity around what the skill may access and increases the chance of over-privileged execution, especially because it also references local credential files and external API calls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are broad common-language requests such as '发朋友圈' and '生成朋友圈文案', making accidental invocation likely in ordinary conversation. Unintended activation is risky here because the skill can perform file writes, external API calls, and possibly network callback setup, so a casual phrase may trigger more capability than users expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file states that all output must follow Chinese expression habits and later requires prompts to be written in English, effectively imposing fixed language behavior. Because no user opt-in or language-selection mechanism is offered, this is a natural-language locale policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs storing QR-code settings and using contact/QR data without clearly warning users that these details will persist on local disk. Contact information and QR images can be personally identifying or business-sensitive, so silent persistence increases privacy and retention risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written entirely in Chinese, including the title, instructions, mapping rules, and usage guidance, with no indication that users may choose another language or locale. Under the policy for natural-language violations, a skill that imposes a specific language without opt-in should be flagged unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The publish script invokes npx openclaw skill publish without pinning a specific package version. Because npx may resolve and execute a package version from the registry at runtime, a compromised latest release, dependency confusion scenario, or unexpected upstream change could lead to arbitrary code execution during publishing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The phrase "When user answers Q4 (是否需要二维码)" indicates a Chinese-language prompt is being used, but this file does not state that the user can choose language or that the locale is intentionally constrained. That can violate language/locale policy when users are not given opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L030 explicitly requires Chinese punctuation, and the surrounding template and required prompts are all written in Chinese. This imposes a specific language/locale on users without any opt-in or alternative language path, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions throughout the file are written as mandatory Chinese-language layout rules and example CTA text, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The POST handler writes raw request payloads and a summary containing all request headers and parsed body contents to local files. This can retain secrets, personal data, tokens, and attacker-supplied content unnecessarily, creating a local data exposure risk and making the skill behave like a passive collector despite having no obvious business need to do so.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/kie-create-task.py (reported line 7)May include surrounding context.

python
import urllib.request
from pathlib import Path

ENDPOINT = "https://api.kie.ai/api/v1/jobs/createTask"


def load_config():

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script accepts an arbitrary callback URL from the command line and forwards it directly to a third-party job API. This creates webhook-capable behavior that is broader than the stated WeChat content-generation purpose and can be abused to send job results or related metadata to attacker-controlled endpoints, increasing data exfiltration and SSRF-style workflow risks in integrated environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script transmits prompts, optional image URLs, and optional callback information to an external vendor API without any explicit disclosure in the code path. In an agent skill context, prompts and images may contain sensitive business, personal, or proprietary marketing material, so silent third-party transmission creates a meaningful privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script takes a URL from task metadata and downloads it to an attacker-influenced output path without validating the destination host, scheme, content type, or file size. If an attacker can influence the callback JSON or upstream task result, this can be abused for SSRF-like access, retrieval of malicious payloads, or planting untrusted files on the local filesystem; this is especially suspicious because it exceeds the stated WeChat content-generation purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/kie-wait-download.py (reported line 34)May include surrounding context.

python
return
    except Exception:
        pass
    subprocess.run(['curl', '-L', url, '-o', str(output_path)], check=True)


def main():

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language description and usage are explicitly Chinese-only ('微信朋友圈营销图生成', Chinese argument examples) and the prompt generated for the model is also hardcoded in Chinese. There is no indication that the user can opt into another language or that the skill is intentionally restricted to a China-specific/localized workflow, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.