Back to skill

Security audit

微信公众号运营工具

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed WeChat publishing workflow, but it asks users to trust an unexplained fixed IP address and store powerful account secrets in local files.

Review this before installing. Do not add 112.8.202.216 to a WeChat allowlist unless the publisher proves why that exact address is needed and who controls it. Store AppSecret and browser session files outside shared or synced workspaces, restrict file permissions, exclude them from Git, and rotate the AppSecret if it may have been exposed. Use the skill only when you intend to create or manage WeChat drafts under that account.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/publish.py:74
Finding

Unexplained third-party IP is prescribed for the WeChat API allowlist

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:237-239, SKILL.md:260-263, scripts/publish.py:74-77, scripts/publish.py:271-276, and references/api_ref.md:79-82
Vulnerability Type: Expansion of an external API trust boundary beyond the privileges required for local execution
Risk Level: Medium

Vulnerable Code Snippet

The documentation and runtime error guidance repeatedly prescribe the following fixed address:

text
112.8.202.216

The runtime behavior containing the vulnerable recommendation is located at:

python
if data["errcode"] == 40164:
    raise Exception(
        f"Error 40164: the IP is not allowlisted. "
        f"Add IP 112.8.202.216 in the WeChat administration console."
    )

The snippet above is an English rendering of the source message at scripts/publish.py:74-77; the security-relevant address and control flow are unchanged.

Technical Analysis

WeChat restricts API access according to an account-level source-IP allowlist. The project instructs users to add a fixed address, 112.8.202.216, but does not establish that this address belongs to the user, the local host, or a trusted service required by the Skill.

This recommendation conflicts with assets/INSTALL.md:34-46, which instructs users to determine and authorize their own outbound IP. The Python scripts communicate directly from the machine executing them to https://api.weixin.qq.com; they do not proxy requests through, connect to, or otherwise depend on the fixed address. Therefore, authorizing that address is not necessary for the declared local publishing workflow and exceeds minimum privilege.

IP allowlisting alone does not disclose the AppSecret or access token. Exploitation additionally requires valid WeChat credentials or a token. Nevertheless, pre-authorizing an unexplained host removes an important defense-in-depth control if those credentials are later compromised.

Attack Path

...[truncated 1154 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove 112.8.202.216 from all documentation, examples, and runtime error messages.
  2. Instruct users to authorize only the actual outbound IP of the machine or server that executes the scripts.
  3. Replace the runtime message with neutral guidance to determine the current outbound IP and verify its ownership.
  4. Require explicit user confirmation before recommending any account-level allowlist modification.
  5. Document how to remove obsolete addresses and periodically review the WeChat allowlist.
  6. If a managed relay is genuinely required, disclose its ownership, purpose, data handling, and security controls, and make its use optional.
  7. Rotate the AppSecret if the unexplained address was previously authorized and credential exposure is suspected.

T08 · Insecure Dependencies

Note
Location
assets/INSTALL.md:60
Finding

Python dependencies are installed without version or integrity pinning

Content
View full analysis

Vulnerability Details

File Location: assets/INSTALL.md:60-65, assets/INSTALL.md:104-108, scripts/publish.py:23-33, and scripts/upload_cover.py:14-18
Vulnerability Type: Unlocked third-party dependency installation
Risk Level: Low

Vulnerable Code Snippet

bash
pip install requests Pillow

Related runtime guidance also recommends unrestricted installation:

python
try:
    import requests
except ImportError:
    print("Missing requests package; install it with: pip install requests")
    sys.exit(1)

try:
    from PIL import Image
except ImportError:
    print("Missing Pillow package; install it with: pip install Pillow")
    sys.exit(1)

The Python snippet above is an English rendering of the user-facing source messages at scripts/publish.py:23-33; package names and installation commands are unchanged.

Technical Analysis

The documented installation command does not constrain package versions and does not verify package hashes. Each installation can therefore resolve to whatever release the configured Python package index currently serves.

requests and Pillow are legitimate, correctly spelled packages, and the project does not configure a suspicious package repository. No malicious dependency is present in the audited files. The risk arises from mutable dependency resolution: a compromised upstream release, compromised package index, malicious index override, or unexpectedly incompatible future version could be installed without review.

Python package installation can execute build backends and installation-related code with the privileges of the invoking user. This makes dependency integrity relevant even though the dependencies are not directly malicious in the reviewed project.

Attack Path

  1. A user follows the installation instructions and runs pip install requests Pillow.
  2. Pip resolves packages from the user's configured package index with ...[truncated 1024 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add a reviewed dependency lock file containing exact versions.
  2. Include cryptographic hashes for every direct and transitive dependency.
  3. Document installation with:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Install dependencies inside a dedicated virtual environment rather than globally or with administrator privileges.
  5. Review and update pinned versions on a controlled schedule after security testing.
  6. Use the official Python Package Index explicitly where organizational policy permits, and warn users against untrusted index overrides.
  7. Add automated dependency vulnerability scanning and lock-file verification to the release process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

代码行为非常具体且有限:读取本地图片、转为 RGB/JPEG、尝试通过调整 JPEG 质量和缩放分辨率来压缩到目标大小,并输出结果信息。它没有实现任何公众号运营全流程中的核心环节,如内容生成、排版、草稿箱写入、定时发布、数据分析或外部 API/技能协同。虽然图片处理可被视为公众号运营中的一个辅助步骤,但声明将技能描述为覆盖完整运营链路,和实际仅有的封面图压缩脚本相比,存在明显的用途夸大与主功能不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description claims a comprehensive WeChat public account operations skill spanning research, writing, image generation, optimization, direct draft writing, proofreading, scheduled publishing, and analytics. The supplied code only implements a specific publishing subtask: loading credentials, calling WeChat APIs, uploading a cover image, converting Markdown to styled HTML, creating a draft payload, and submitting it to the draft box. This is not harmful or undeclared in a suspicious sense, but it is a material description-behavior mismatch because the declared primary purpose is much broader than the actual implemented behavior in this chunk. The code does align with the narrower subset of 'API直写草稿箱/排版' and draft submission for WeChat articles.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码的主要目的与描述存在明显不一致。声明描述的是一个覆盖公众号运营完整链路的综合技能,但提供的代码块只执行非常有限的操作:读取本地 wechat_credentials.json 中的凭证、获取微信 access token、检查图片大小并上传图片到永久素材库。虽然这一步与公众号发布流程相关,可视为整体流程中的支持性子功能,但它无法代表所声明的“全流程运营”能力,且未实现描述中的大部分关键环节。因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill normalizes storing公众号 AppID/AppSecret in a predictable workspace file path, which increases the risk of accidental exposure to other tools, logs, or users with workspace access. Because these credentials enable API access to a live publishing account, compromise could permit unauthorized draft creation, content manipulation, or broader account abuse depending on granted permissions.

Content

Scanner excerpt · SKILL.md (reported line 239)May include surrounding context.

md
**前置条件**:
- 拥有公众号 AppID + AppSecret(管理员后台查看)
- 调用服务器 IP `112.8.202.216` 已加入 IP 白名单
- 凭证保存在 `{workspace}/wechat_credentials.json`

**完整流程**(由 `wechat-oa-draft` 技能自动执行):

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Describing direct Access Token retrieval is legitimate for the integration, but without safeguards it indicates a workflow that may expose bearer tokens in logs, scripts, or transient files. Since access tokens can authorize API operations against the公众号 account, leakage could enable unauthorized content actions until expiry.

Content

Scanner excerpt · SKILL.md (reported line 244)May include surrounding context.

完整流程(由 wechat-oa-draft 技能自动执行):

text
1. 获取 Access Token(有效期2小时)
   GET /cgi-bin/token

2. 上传封面图(永久素材接口 ⚠️ 非临时素材)

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The guide explicitly instructs creation of a credentials file containing an AppSecret, which is a form of credential materialization on disk. In the context of a WeChat publishing skill, compromise of that file could grant API access to the official account, enabling unauthorized publishing workflows, content tampering, or broader account misuse; the risk is elevated because the file is user-created in a general working directory and the document lacks handling safeguards.

Content

Scanner excerpt · assets/INSTALL.md (reported line 50)May include surrounding context.

3. 创建凭证文件

在你的工作目录创建 wechat_credentials.json:

json
{

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_ref.md (reported line 6)May include surrounding context.

md
## 基础信息

- **API 域名**: `https://api.weixin.qq.com`
- **Access Token**: 每次调用前重新获取,有效期 7200 秒
- **必需前提**: 调用 IP 已在 mp.weixin.qq.com 后台加入白名单

## 核心 API 端点

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_ref.md (reported line 54)May include surrounding context.

md
## 基础信息

- **API 域名**: `https://api.weixin.qq.com`
- **Access Token**: 每次调用前重新获取,有效期 7200 秒
- **必需前提**: 调用 IP 已在 mp.weixin.qq.com 后台加入白名单

## 核心 API 端点

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_ref.md (reported line 84)May include surrounding context.

md
python publish.py <文章.md路径> <封面图路径> [摘要]

功能:
  1. 读取 wechat_credentials.json 获取 AppID 和 AppSecret
  2. 获取 Access Token
  3. 上传封面图到永久素材
  4. 将 Markdown 转换为微信草稿 JSON

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/credentials_guide.md (reported line 43)May include surrounding context.

md
python publish.py <文章.md路径> <封面图路径> [摘要]

功能:
  1. 读取 wechat_credentials.json 获取 AppID 和 AppSecret
  2. 获取 Access Token
  3. 上传封面图到永久素材
  4. 将 Markdown 转换为微信草稿 JSON

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/credentials_guide.md (reported line 79)May include surrounding context.

md
python publish.py <文章.md路径> <封面图路径> [摘要]

功能:
  1. 读取 wechat_credentials.json 获取 AppID 和 AppSecret
  2. 获取 Access Token
  3. 上传封面图到永久素材
  4. 将 Markdown 转换为微信草稿 JSON

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/publish.py (reported line 8)May include surrounding context.

python
python publish.py <文章.md路径> <封面图路径> [摘要]

功能:
  1. 读取 wechat_credentials.json 获取 AppID 和 AppSecret
  2. 获取 Access Token
  3. 上传封面图到永久素材
  4. 将 Markdown 转换为微信草稿 JSON

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/publish.py (reported line 273)May include surrounding context.

python
python publish.py <文章.md路径> <封面图路径> [摘要]

功能:
  1. 读取 wechat_credentials.json 获取 AppID 和 AppSecret
  2. 获取 Access Token
  3. 上传封面图到永久素材
  4. 将 Markdown 转换为微信草稿 JSON

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/upload_cover.py (reported line 22)May include surrounding context.

python
python publish.py <文章.md路径> <封面图路径> [摘要]

功能:
  1. 读取 wechat_credentials.json 获取 AppID 和 AppSecret
  2. 获取 Access Token
  3. 上传封面图到永久素材
  4. 将 Markdown 转换为微信草稿 JSON

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_ref.md (reported line 13)May include surrounding context.

md
功能:
  1. 读取 wechat_credentials.json 获取 AppID 和 AppSecret
  2. 获取 Access Token
  3. 上传封面图到永久素材
  4. 将 Markdown 转换为微信草稿 JSON
  5. 提交草稿到公众号

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/publish.py (reported line 9)May include surrounding context.

python
功能:
  1. 读取 wechat_credentials.json 获取 AppID 和 AppSecret
  2. 获取 Access Token
  3. 上传封面图到永久素材
  4. 将 Markdown 转换为微信草稿 JSON
  5. 提交草稿到公众号

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/publish.py (reported line 61)May include surrounding context.

python
功能:
  1. 读取 wechat_credentials.json 获取 AppID 和 AppSecret
  2. 获取 Access Token
  3. 上传封面图到永久素材
  4. 将 Markdown 转换为微信草稿 JSON
  5. 提交草稿到公众号

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/publish.py (reported line 301)May include surrounding context.

python
功能:
  1. 读取 wechat_credentials.json 获取 AppID 和 AppSecret
  2. 获取 Access Token
  3. 上传封面图到永久素材
  4. 将 Markdown 转换为微信草稿 JSON
  5. 提交草稿到公众号

Credential Access

High
Category
Privilege Escalation
Confidence
85% confidence
Finding

The script hardcodes a credentials filename and loads AppID/AppSecret from a JSON file in the working directory. In an agent-skill context, local plaintext secrets in predictable locations are easier to leak via accidental inclusion, weak filesystem permissions, or misuse by other tooling, making credential compromise more likely.

Content

Scanner excerpt · scripts/publish.py (reported line 38)May include surrounding context.

python
# ============== 配置 ==============
API_BASE = "https://api.weixin.qq.com"
CREDENTIALS_FILE = "wechat_credentials.json"


# ============== 凭证读取 ==============

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The request sends appsecret as a query parameter when obtaining the access token. Although this is over HTTPS and matches the provider API pattern, query-string secrets are more likely to be exposed through proxy logs, debug tooling, monitoring systems, or exception traces than secrets placed in headers or secure secret-handling abstractions.

Content

Scanner excerpt · scripts/publish.py (reported line 69)May include surrounding context.

python
"secret": appsecret
    }

    print("📡 获取 Access Token...")
    resp = requests.get(url, params=params, timeout=30)
    data = resp.json()

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Broad trigger phrases such as common publishing-related language can cause the skill to activate in contexts the user did not intend. In a skill that touches account publication, automation, and credential-adjacent workflows, accidental activation raises the chance of unintended account actions, disclosure of sensitive workspace files, or inappropriate tool use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs users to persist browser login state and use API-based publication with stored credentials, but it does not prominently warn about account takeover, token leakage, unauthorized publishing, or privacy implications of saved session artifacts. In the context of a social-media publishing skill, these omissions are more dangerous because misuse directly affects a real external account and can lead to unauthorized posts or credential compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installation guide tells users to store the WeChat AppSecret in a plaintext JSON file in the working directory, but gives no guidance on file permissions, secure storage, git exclusion, or environment-based secret handling. In a skill that automates publishing to an official account, theft of this secret can enable unauthorized API access, draft manipulation, or account abuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api_ref.md (reported line 49)May include surrounding context.

$body = $memStream.ToArray() $memStream.Close()

$url = "https://api.weixin.qq.com/cgi-bin/material/add_material?access_token=$token&type=image" $resp = Invoke-WebRequest -Uri $url -Method POST -Body $body -ContentType "multipart/form-data; boundary=$boundary" $resp.Content

text

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and usage text are written entirely in Chinese, and the script later prints user-facing status and error messages only in Chinese. This imposes a specific language on users without opt-in or explanation, which matches the natural-language locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.