Back to skill

Security audit

微信读书轨迹墙 Weread Timeline Wall

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local tool for generating a WeRead reading-history page, with manageable privacy and session-storage risks users should understand.

Install only if you are comfortable using browser automation with your WeRead account. Keep the saved profile state and exported JSON/HTML private, avoid committing them to repositories or synced folders, and consider pinning dependencies before repeated or shared use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
pip install -r scripts/requirements.txt

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill clearly describes capabilities that read local files, write output files, and access the network, but it does not declare any explicit tool scope or permissions boundary. That mismatch is dangerous because an agent or runtime may grant broader access than users expect, reducing transparency and increasing the chance of unintended file access, data exfiltration, or unsafe automation against a logged-in account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persists Playwright storage state to a local JSON file, which can contain reusable authenticated session cookies or tokens for the user's WeRead account. If that file is stored insecurely, committed to a repo, synced to cloud storage, or read by another local user/process, an attacker could hijack the session without needing the user's QR login.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency specifier playwright>=1.40 is unpinned, so installs may resolve to different versions over time. That creates supply-chain and reproducibility risk: a future compromised or incompatible release could be pulled into the skill without review.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
playwright>=1.40
Pillow>=10.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

Pillow>=10.0 is unpinned, which means dependency resolution may select any newer release, including versions with newly introduced vulnerabilities or behavioral changes. In this skill, Pillow likely processes images/screenshots, so a vulnerable image library can increase exposure to malicious image parsing bugs and denial-of-service issues.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
playwright>=1.40
Pillow>=10.0

Unverifiable Dependency: Pillow has 16 known advisory(ies) (CVE-2016-2533 (Pillow buffer overflow in ImagingPcdDecode); CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2021-27922 (Pillow Uncontrolled Resource Consumption) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest references Pillow without pinning to a known-safe release, and Pillow has a history of security advisories including image parsing and resource-consumption issues. Because this skill generates HTML and screenshots and may handle external image content such as book covers, the lack of version pinning makes it impossible to verify whether deployment will use a patched release.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script can export detailed reading-history metadata to JSON, including titles, authors, categories, note counts, completion state, and activity timestamps. While this is not code execution, it creates a privacy-sensitive local artifact that may reveal personal interests and behavior if exposed through shared folders, backups, or accidental publication.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.