Back to skill

Security audit

Wechat Article Search - 微信公众号文章搜索

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but one optional link-resolution path can make requests to unvalidated URLs from search results, which is risky on private networks.

Install only if you are comfortable running a web-scraping tool that contacts Sogou and WeChat. Use it in a restricted network environment, avoid --ua-rotate unless you have a legitimate compatibility reason, and avoid --resolve-url or --fetch-content until URL allowlisting is added. Prefer pinned dependency versions in an isolated virtual environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:36
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
search.py:135
Finding

Insufficient URL Validation Permits Blind Server-Side Request Forgery

Content
View full analysis
str: h = (href or "").strip() if h.startswith("/"): return "https://weixin.sogou.com" + h return h ``` The parser obtains the URL from remote HTML without validating its host, scheme, port, or resolved address: ```python title = _safe_text(a.get_text(" ", strip=True)) href = _normalize_result_url(a.get("href") or "") ``` When URL resolution or content fetching is requested, the extracted URL is passed to the resolver: ```python real = _resolve_real_url( it.get("url", ""), timeout=timeout, ua_candidates=ua_cands, retries=retries, retry_delay=retry_delay, ) or "" ``` The resolver then makes a request to that URL: ```python def _resolve_real_url( url: str, timeout: float = 10.0, ua_candidates: Optional[List[str]] = None, sleep_s: float = 0.2, retries: int = 1, retry_delay: float = 0.3, ) -> Optional[str]: direct = _extract_real_from_url(url) if direct: return direct r, _ = _request_with_retry( url, timeout=timeout, allow_redirects=False, ua_candidates=ua_candidates, retries=retries, retry_delay=retry_delay, ) if not r: return None time.sleep(max(0.0, sleep_s)) loc = r.headers.get("Location", "").strip() if not loc: return None if loc.startswith("/"): loc = "https://weixin.sogou.com" + loc out = _extract_real_from_url(loc) or loc return _normalize_result_url(out) ``` ### Technical Analysis Search-result HTML is obtained from an external service and must be treated as untrusted. In the primary parsing path, any absolute URL found in a matchin ...[truncated 2330 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises and documents network access and optional file output, but it does not declare any explicit tool scope or permissions boundary. That creates a least-privilege gap: an agent or runtime may invoke a networked, file-writing skill without clear user-visible authorization constraints, increasing the chance of unintended external requests or writes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is broad enough that an agent could route loosely related requests about WeChat articles or public-account content into this skill without confirming user intent. Because the skill performs live web requests and can optionally do further fetching, overbroad triggering can cause unnecessary data egress, unexpected scraping activity, or actions the user did not specifically request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file mandates a strict output template using Chinese field labels such as '标题' and '摘要' and says results 'must' follow that format. This imposes a specific language/locale on responses without offering the user a language choice or documenting that the skill is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Built-in User-Agent rotation is a common anti-detection/anti-rate-limit evasion technique and is not necessary for ordinary article search functionality. In this context it increases suspicion because it can help sustain scraping against target defenses and masks client identity across repeated requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as returning article search metadata, but the implementation can also fetch and return full article body text via the fetch_content path. This expands the data-access scope beyond the declared purpose, creating a capability mismatch that can surprise users, operators, or policy controls and may enable unauthorized content collection at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file contains user-facing natural-language descriptions and command-line help text exclusively in Chinese. Under the policy, forcing a specific language without opt-in or an explicit region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The code optionally resolves intermediary Sogou links into direct WeChat article URLs, which exceeds a simple 'return links from search results' description. While not inherently malicious, this bypasses an indirection layer and changes the nature of what destinations are exposed and subsequently fetched.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.