Back to skill

Security audit

Audio to WeChat Article

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a WeChat article workflow, but its pipeline can execute scripts from hardcoded personal paths outside the reviewed package and silently inserts a default author.

Install only if you are comfortable reviewing or fixing the pipeline first. The main risk is not hidden network exfiltration or persistence; it is that the wrapper may run whatever Python files exist at hardcoded local paths and may put a fixed author name into publish-ready Markdown unless overridden.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/compose_wechat_markdown.py:8
Finding

Unapproved Default Author Attribution in Generated Articles

Content
View full analysis
3 else '' author = sys.argv[4] if len(sys.argv) > 4 else '阿爪' data = json.loads(src.read_text(encoding='utf-8')) title = data.get('title', '未命名文章') summary = data.get('summary', '') body = data.get('body', '') fm = ['---', f'title: {title}', f'author: {author}', f'summary: {summary}'] if cover: fm.append(f'coverImage: {cover}') fm.append('---\n') ``` The publishing handoff also prescribes the same identity: ```yaml --- title: ... author: 阿爪 summary: ... coverImage: relative/or/absolute/path --- ``` ### Technical Analysis The Markdown composer inserts a specific third-party author identity whenever the caller does not explicitly supply an author argument. The reference documentation reinforces this value as part of the publishing contract. Authorship cannot safely be inferred merely because an optional argument was omitted. This behavior modifies publication metadata without establishing that the named party created the source material or that the user approved the attribution. Because the output is designed for direct handoff to a WeChat publishing workflow, the inserted identity can persist into externally published content. This is classified as instruction hijacking because the Skill imposes an unrelated identity on generated output rather than preserving user intent or requesting the missing metadata. ### Attack Path 1. A user requests conversion of audio, notes, or a transcript into a WeChat article. 2. The pipeline calls `compose_wechat_markdown.py` without the optional author argument. 3. The script silently assigns the hardcoded default author. 4. The generated Markdown includes that i ...[truncated 620 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/audio_to_article_pipeline.py:5
Finding

Execution of Unreviewed Scripts Through Hardcoded External Paths

Content
View full analysis
[coverImage] [qrImage]" BASE = Path('/Users/meizi/.openclaw/workspace/skills/audio-to-wechat-article/scripts') WHISPER = Path('/Users/meizi/.openclaw/workspace/skills/meeting-minutes-whisper/scripts/transcribe_and_minutes.py') def run(cmd): subprocess.run(cmd, check=True) ``` The external transcription script is executed directly: ```python run(['/usr/bin/python3', str(WHISPER), str(src), '--language', 'Chinese', '--model', model, '--title', prefix.name, '--output-dir', str(out_dir)]) ``` The pipeline also executes article-processing scripts from the hardcoded external base directory instead of the reviewed package directory: ```python run(['/usr/bin/python3', str(BASE / 'build_article_brief.py'), str(text_src), str(brief_path)]) run(['/usr/bin/python3', str(BASE / 'draft_article_json.py'), str(text_src), str(article_json)]) run(['/usr/bin/python3', str(BASE / 'compose_wechat_markdown.py'), str(article_json), str(markdown_path), cover]) ``` ### Technical Analysis The pipeline does not resolve its bundled scripts relative to its own installed location. Instead, it invokes Python files under fixed absolute paths in another user's workspace. Those files are outside the reviewed artifact and are not authenticated, hashed, version-pinned, or otherwise verified before execution. Although the subprocess calls use argument arrays and do not expose shell-command injection, the trust boundary remains unsafe: replacing any script at the hardcoded paths changes the code that the apparently legitimate pipeline executes. This creates a local tool-hijacking opportunity ...[truncated 1684 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Overstating capabilities in a content-processing skill is dangerous because it can cause users or orchestrators to route rich inputs, including meeting recordings and QR assets, into a workflow that does not actually process them as claimed. In this context, the risk is less about code execution and more about deceptive or unreliable automation around potentially sensitive business content.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Overstating capabilities in a content-processing skill is dangerous because it can cause users or orchestrators to route rich inputs, including meeting recordings and QR assets, into a workflow that does not actually process them as claimed. In this context, the risk is less about code execution and more about deceptive or unreliable automation around potentially sensitive business content.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Overstating capabilities in a content-processing skill is dangerous because it can cause users or orchestrators to route rich inputs, including meeting recordings and QR assets, into a workflow that does not actually process them as claimed. In this context, the risk is less about code execution and more about deceptive or unreliable automation around potentially sensitive business content.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The workflow directs the system to 'Draft WeChat article,' and the example requests are exclusively Chinese-language and WeChat-publication oriented. The file does not state that this locale/platform constraint is optional or user-selected, which can violate language/locale choice expectations unless clearly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes typical user requests such as '根据会议录音写一篇可发文章' and '录音转文字后直接出公众号成稿' but does not define clear trigger constraints, exclusions, or when the skill should not activate. Because these examples resemble ordinary user requests rather than narrowly scoped invocation phrases, they may overlap with normal conversation and cause unintended activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The helper unconditionally executes subprocesses, and the main flow invokes external Python scripts on the provided source file. Although subprocess use is central to the pipeline, this file contains no visible warning, logging, or comments explaining that external tools will be run on the user's data.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/audio_to_article_pipeline.py (reported line 11)May include surrounding context.

python
def run(cmd):
    subprocess.run(cmd, check=True)


def ensure_text_source(src: Path, prefix: Path) -> Path:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This script creates an output directory and then generates multiple output files later in the pipeline, but the code provides no confirmation prompt, log message, comment, or docstring warning that it will write artifacts to disk. For a code-file review under SQP-2, these file-creation operations lack visible user disclosure beyond the usage string.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script hard-codes '--language', 'Chinese' when invoking the transcription tool, which imposes a specific language/locale without offering user opt-in or selection. Under SQP-3, this is a natural-language policy concern because the locale choice is enforced rather than configurable or explicitly justified.

Content

No source excerpt is available for this finding.

Tainted flow: 'text' from pathlib.Path.read_text (line 21, file read) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/compose_wechat_markdown.py (reported line 22)May include surrounding context.

python
fm.append(f'coverImage: {cover}')
    fm.append('---\n')
    text = '\n'.join(fm) + body.strip() + '\n'
    out.write_text(text, encoding='utf-8')
    print(str(out))

if __name__ == '__main__':

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script hardcodes Chinese trigger patterns, fallback strings, usage text, and article body content, which constrains output to Chinese regardless of user preference. This is a natural-language policy concern because the skill does not offer any language or locale opt-in or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Tainted flow: 'data' from pathlib.Path.read_text (line 38, file read) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/draft_article_json.py (reported line 39)May include surrounding context.

python
summary = core[:90]
    body = f"# {title}\n\n{core}\n\n先说结论:这段内容值得被写成公众号文章,不是因为信息多,而是因为它有一个可以被提炼的核心判断。\n\n## 为什么这件事值得写\n\n把原始录音或文字稿直接发出去,通常是不可读的。真正值钱的是先提炼核心观点,再把它改造成适合公众号阅读的结构。\n\n## 这篇后续应该怎么扩\n\n- 补一个更强的开头钩子\n- 拆成 3-5 个主体部分\n- 加上案例或截图\n- 最后给出一句收束判断\n"
    data = {'title': title, 'summary': summary, 'body': body, 'core_point': core}
    out.write_text(json.dumps(data, ensure_ascii=False, indent=2), encoding='utf-8')
    print(str(out))

if __name__ == '__main__':

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title, summary, and body instruct generation of a Chinese public-account article, effectively constraining output language and locale. There is no indication that the user opted into Chinese output or that the locale restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The value of core_point is written entirely in Chinese and there is no surrounding text indicating that the user opted into Chinese output or that the skill is explicitly limited to a Chinese-language context. This can violate language/locale policy because it implicitly forces a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The title, summary, heading, and instructions all prescribe producing a WeChat public-account article in Chinese, with no indication that the user can choose another language or locale. This is a natural-language policy concern because the skill appears to enforce a specific language context without opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file content is entirely in Chinese and presents the workflow description only in that language, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill implicitly requires a specific language without documenting opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The JSON content contains only Chinese-language title, summary, and body text with no indication that the language is optional, configurable, or justified by a region-specific purpose. This can violate a language/locale policy when a skill implicitly enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill mentions optional publishing to a WeChat draft box without clearly warning that content may be transmitted to an external service. For a workflow involving meeting audio, transcripts, and business materials, this can lead to unintended disclosure of sensitive information if users do not realize a publish step leaves the local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description and output expectations are oriented toward Chinese/WeChat article production, including Chinese trigger terms and Chinese output structure labels, but do not explicitly state that the skill is China/WeChat-specific or that the user can choose the output language. This can amount to an implicit language/locale constraint without clear opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The markdown includes a fixed non-user-selectable author value, "阿爪", in the required frontmatter contract. This can constitute a language/locale policy issue because it prescribes a specific locale-dependent value without stating that users may choose their own language or author representation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The instruction says to turn material into "publishable WeChat prose," which imposes a specific platform and implied locale/style requirement in natural language. The file does not indicate that this format is optional or user-selected, so it may conflict with policies requiring language or locale choice unless this scope is explicitly justified elsewhere.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example command hard-codes --language Chinese, which is a natural-language locale choice presented as the preferred workflow. The document does not offer an explicit user choice or explain that this is only an example for Chinese-language audio, so it can be read as mandating a specific language setting.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON file contains natural-language invocation guidance asking to continue writing an article based on another file, but it does not define when this content should be used, what exact trigger phrases apply, or any exclusions. In a manifest-scoped file, that lack of specificity can contribute to unintended activation or overly broad matching.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s title, author, summary, and body are all written in Chinese, with no indication that language choice is optional or that the skill is intentionally region-specific. This creates a natural-language locale policy concern because the content implicitly fixes one language without offering user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.