Back to skill

Security audit

aigc-web-push · AI内容生成与全网推送

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real AI content publishing skill, but it needs review because it stores and transmits publishing credentials and content with weak destination controls and includes draft-deletion capability.

Review this skill before installing if it will connect to real WeChat or cloud publishing accounts. Keep config.json private, do not commit or share skillKey/openId, verify apiBase stays on the intended HTTPS service, confirm the target account or cloud instance before each push, and avoid cleanupDrafts unless you intentionally want drafts cleared. Prefer a pinned install command or a reviewed release.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
push-to-cloud.js:67
Finding

Configurable HTTP endpoint can receive publishing credentials and user content

Content
View full analysis
{ const u = new URL(apiBase); const lib = u.protocol === 'http:' ? http : https; const data = Buffer.from(JSON.stringify(body), 'utf8'); const req = lib.request( { hostname: u.hostname, port: u.port || (u.protocol === 'http:' ? 80 : 443), ``` `push-to-cloud.js:141-145`: ```javascript const openId = String(cfg.openId || '').trim(); if (!openId) throw new Error('config.json is missing openId'); const skillKey = String(cfg.skillKey || '').trim(); if (!skillKey) throw new Error('config.json is missing skillKey'); const apiBase = String(cfg.apiBase || DEFAULT_API).trim() || DEFAULT_API; ``` `push-to-cloud.js:176-188`: ```javascript body = { action: 'sendToCloud', openId, skillKey, serverInstanceIds, categoryId, title: titleFromHtml(content), content, publishMode, ...(coverHtml ? { coverHtml } : {}), }; ``` `push-to-wechat-mp.js:119-135`: ```javascript function postJson(urlStr, body, timeoutMs = 120000) { const payload = JSON.stringify(body); const u = new URL(urlStr); const lib = u.protocol === 'https:' ? https : http; const port = u.port || (u.protocol === 'https:' ? 443 : 80); return new Promise((resolve, reject) => { const req = lib.request( { hostname: u.hostname, port, path: u.pathname + u.search, method: 'POST', headers: { 'Content-Type': 'application/json; charset=utf-8', 'Content-Length': Buffer.byteLength(payload, 'utf8'), ``` `push-to-wechat-mp.js:295-303`: ```javascript const body = { action: 'sendToWechat', openId: cfg ...[truncated 2080 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
push-to-cloud.js:28
Finding

Authorization credential is stored in a plaintext project configuration file

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:18
Finding

Unpinned npx installation command executes mutable third-party package code

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
push-to-wechat-mp.js:181
Finding

Client forwards unlisted WeChat AppIDs instead of enforcing the configured account boundary

Content
View full analysis
a && a.selected && a.appId); if (!selected) { return undefined; } const sid = String(selected.appId).trim(); if (isPlatformAppId(sid)) return undefined; return sid; } const tid = String(targetAppIdFromCli).trim(); if (isPlatformAppId(tid)) return undefined; const found = accounts.some( (a) => a && a.appId && String(a.appId).toLowerCase() === tid.toLowerCase() ); if (!found) { console.error( 'Notice: the supplied AppID is absent from config.accounts; publishing will still continue.' ); } return tid; } ``` `push-to-wechat-mp.js:305-310`: ```javascript if (imgUrls && imgUrls.length > 0) { body.imgUrls = imgUrls; } if (appId) { body.appId = appId; } ``` ### Technical Analysis The client checks whether the command-line AppID appears in `config.accounts`, but a failed check produces only a warning. The unlisted identifier is still returned and included in the authenticated publishing request. This means the locally configured account inventory is advisory rather than an enforced target boundary. A caller capable of influencing command-line arguments can direct the client to request publication to an arbitrary AppID. Actual cross-account publication depends on the remote API's server-side authorization controls. The project does not contain that backend, so successful privilege escalation cannot be confirmed from this artifact alone. Nevertheless, the client fails closed only for neither malformed nor unauthori ...[truncated 1013 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (27)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest sets alwaysApply: true, which causes this rewriting behavior to activate broadly without an explicit user trigger or scope check. For a skill that rewrites text style, this can silently alter unrelated user content, override user intent, and increase the chance of unintended transformations across conversations or workflows.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · Humanizer.md (reported line 170)May include surrounding context.

md
**After:**
> The term is primarily promoted by Dutch institutions, not by the people themselves. You don't say "Netherlands, Europe" as an address, yet this mislabeling continues in official documents.
**Before:**
> The new policy — announced without warning — affects thousands of workers. The changes -- long overdue according to critics -- will take effect immediately.
**After:**
> The new policy, announced without warning, affects thousands of workers. The changes, long overdue according to critics, will take effect immediately.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · Humanizer.md (reported line 172)May include surrounding context.

md
**After:**
> The term is primarily promoted by Dutch institutions, not by the people themselves. You don't say "Netherlands, Europe" as an address, yet this mislabeling continues in official documents.
**Before:**
> The new policy — announced without warning — affects thousands of workers. The changes -- long overdue according to critics -- will take effect immediately.
**After:**
> The new policy, announced without warning, affects thousands of workers. The changes, long overdue according to critics, will take effect immediately.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
2. 生成主 HTML 后,若页面中没有引用图片,可再按 `design_cover.md` 根据 title 生成封面 HTML,命名为 `你的文件_cover.html`(与主 HTML 同目录;云电脑与公众号推送均会自动附带)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
2. 生成主 HTML 后,若页面中没有引用图片,可再按 `design_cover.md` 根据 title 生成封面 HTML,命名为 `你的文件_cover.html`(与主 HTML 同目录;云电脑与公众号推送均会自动附带)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The guidance explicitly encourages use of first-person voice (e.g. adding “我”) as a way to make text sound more human, without requiring user consent. This can change authorship signals, misrepresent the user's intended persona, and in some contexts make generated or edited content appear deceptively personal or falsely attributable to a human speaker.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs 'File mode' to rewrite the referenced file in place. That creates a real integrity risk because invoking the skill on a file can modify user data without an explicit confirmation, preview, backup, or warning, and the skill is marked alwaysApply, which increases the chance of unintended edits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This skill explicitly supports generating content and pushing it to WeChat public accounts or third-party cloud-managed sites, but the README does not prominently warn that user-provided or AI-generated content may be published externally. In this context, omission is meaningful because the skill’s core purpose is cross-platform publishing, so users may unintentionally expose sensitive, copyrighted, or unreviewed content to public channels.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions tell the AI to save wizard-generated configuration into config.json, while the same document states it may contain authorization material such as account lists, selected targets, skillKey, and API settings. Storing this data in a plain local file without any sensitivity warning, access guidance, or secret-handling controls creates a risk of credential exposure and subsequent unauthorized publishing or account actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The push workflow instructs transmission of user content, target account identifiers, cloud instance selection, and possibly media URLs to a remote API, but provides no privacy, data handling, or consent warning. In a content-publishing skill, silent external transmission is especially sensitive because generated drafts, account metadata, and publishing targets may be business-confidential or personal.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises content generation and publishing, but it also documents a destructive administrative action, cleanupDrafts, that deletes/clears drafts. Hidden or under-emphasized privileged capabilities increase the chance that an agent or user invokes them without understanding the impact, causing loss of content or abuse against connected accounts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This endpoint is tied to a destructive operation, cleanupDrafts, which can remove drafts from a connected WeChat account. Because it performs state-changing remote actions and the document says timeouts may still mean success, misuse or accidental invocation could cause irreversible content loss without reliable operator awareness.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

清空草稿箱

POST https://api.pcloud.ac.cn/openAccessService:

json
{

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file-level description is written entirely in Chinese and provides no indication that another language is available or that the locale is intentionally limited. Under the policy for natural-language violations, forcing a specific language without user choice should be flagged unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
{
  "_fileRole": "字段说明 + 示例。正式 config.json 只保留向导输出的业务键(去掉本文件中的 _fileRole / fieldsHelp / *Example*)。",
  "fieldsHelp": {
    "apiBase": "缺省 https://api.pcloud.ac.cn/openAccessService",
    "openId": "扫码得到的微信 openId,禁止编造",
    "skillKey": "扫码后服务端签发的业务随机密钥,与 openId 绑定;推送必带。重新扫码会轮换",
    "accounts": "公众号列表;selected:true 为默认推送目标",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · config.example.json (reported line 4)May include surrounding context.

json
{
  "_fileRole": "字段说明 + 示例。正式 config.json 只保留向导输出的业务键(去掉本文件中的 _fileRole / fieldsHelp / *Example*)。",
  "fieldsHelp": {
    "apiBase": "缺省 https://api.pcloud.ac.cn/openAccessService",
    "openId": "扫码得到的微信 openId,禁止编造",
    "skillKey": "扫码后服务端签发的业务随机密钥,与 openId 绑定;推送必带。重新扫码会轮换",
    "accounts": "公众号列表;selected:true 为默认推送目标",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · config.example.json (reported line 12)May include surrounding context.

json
{
  "_fileRole": "字段说明 + 示例。正式 config.json 只保留向导输出的业务键(去掉本文件中的 _fileRole / fieldsHelp / *Example*)。",
  "fieldsHelp": {
    "apiBase": "缺省 https://api.pcloud.ac.cn/openAccessService",
    "openId": "扫码得到的微信 openId,禁止编造",
    "skillKey": "扫码后服务端签发的业务随机密钥,与 openId 绑定;推送必带。重新扫码会轮换",
    "accounts": "公众号列表;selected:true 为默认推送目标",

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The YAML front matter uses an overly generic description together with alwaysApply: true, which can cause this skill's constraints to be injected into unrelated tasks. In an agent setting, broad unconditional application can override higher-priority user intent, create prompt-scope bleed, and unexpectedly influence downstream HTML/code generation in contexts where this skill was not explicitly requested.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template hard-codes <html lang="zh-CN">, which imposes a specific language/locale on all generated output. The document does not provide an opt-in, user choice, or justification that this skill is only for a China-specific use case, so it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language instructions force a specific language/locale for users reading or invoking the skill, and the file does not mention any user opt-in or justified region-specific limitation. Under the policy, fixed language behavior without choice or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The front matter sets alwaysApply: true, causing this rule file to activate globally without trigger constraints. In an agent skill that influences content generation, unconditional activation can override safer context-specific behavior, increase prompt-surface exposure, and make unintended instructions apply in unrelated tasks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's primary usage documentation is entirely in Chinese, and later runtime messages are also Chinese-only. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The script reads sensitive identifiers from config.json (openId, skillKey) and transmits them, along with article HTML, image/video URLs, and selected instance IDs, to a remote API endpoint that can be overridden via cfg.apiBase. In the context of an auto-publishing skill, external transmission is expected, but allowing a configurable destination without origin allowlisting or stronger validation increases the risk of credential and content exfiltration if the config is tampered with or misconfigured.

Content

Scanner excerpt · push-to-cloud.js (reported line 25)May include surrounding context.

js
const path = require('path');
const { URL } = require('url');

const DEFAULT_API = 'https://api.pcloud.ac.cn/openAccessService';
const DIR = __dirname;

function readJson(name) {

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file's natural-language interface is entirely in Chinese, including usage documentation and user-facing messages, with no indication that another language is supported or that the language choice is configurable. This creates a locale/language policy concern because the skill effectively mandates one language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
push.js:34