Back to skill

Security audit

WeChat Official Account Full-Auto Publisher

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent WeChat draft automation tool, but it uses live account session cookies and internal backend requests with enough account-impacting authority that users should review it carefully before installing.

Install only if you are comfortable letting local scripts operate inside an authenticated WeChat public-account browser session. Use a dedicated profile and account where possible, keep the profile directory out of Git/cloud/shared folders, avoid sharing logs or screenshots that show tokens, review any deletion command before running it, and manually inspect the draft before public posting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documentation materially understates and misstates behavior: it references safe-sounding draft upload automation, but the detected behavior includes use of internal WeChat backend interfaces, browser-attached cookies/session reuse, and undeclared draft deletion capability. This mismatch is dangerous because users cannot give informed consent about account-impacting actions, and hidden destructive or unsupported operations may break accounts, delete content, or violate platform expectations.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
| A 指令框 + 知识库 | 指令框放上面的一屏版,再把 `SKILL.md`、`references/`、`assets/design-template.html` 全传进知识库/文件区 | 最稳,推荐 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

md
python scripts/gzh_save.py --title "标题" --md 正文.md --cover ./out/cover_900x383.png \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 333)May include surrounding context.

md
python scripts/gzh_save.py --title "标题" --md 正文.md --cover ./out/cover_900x383.png \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire README instructs the user in Chinese and explicitly tells the user to speak to the agent using a Chinese prompt, with no indication that other languages are supported or that the language requirement is optional. This appears to impose a specific language/locale on users without opt-in, which matches the language-policy violation criterion.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill describes and instructs use of scripts that can read/write local files, use browser session state, make network requests to WeChat backends, and execute shell commands, but it declares no explicit tool scope or permission boundaries. That increases the chance a user or host platform will invoke it without understanding the full capability and data exposure surface, especially because login cookies and draft content are handled locally and sent to remote services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description omits a clear warning that the workflow will transmit article content and authenticated session-backed requests to WeChat platform backends during automated draft upload. Because the process uses browser profile state and remote submission, users need explicit disclosure to understand privacy, account, and platform-risk implications before running it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description begins with "Use when 用豆包智能体做公众号文章并自动发布到草稿箱", which describes a general situation rather than a specific invocation trigger or bounded context. It does not provide explicit trigger phrases, exclusions, or negative examples, so it could overlap with many ordinary article-writing requests and cause unintended activation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill tells the generated article not to solicit private-channel contact, but the skill document itself solicits direct WeChat contact and points to an external storefront. This inconsistency can normalize off-platform contact and create a social-engineering path where users may seek help and end up sharing sensitive account details, logs, or content outside controlled channels.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document mandates converting timestamps to Beijing time and requires date rendering in Chinese month/day format, then instructs the agent to ask the user for today's date rather than adapting to the user's locale. This is a natural-language locale policy constraint that is imposed globally in the workflow without offering a language or regional choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Lines L030-L032 state that titles are only allowed to use Chinese plus a narrow set of punctuation and half-width alphanumerics, which imposes a specific language/locale constraint. The file does not present this as an optional preference or provide user opt-in, so it reads as a forced language policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document requires Chinese-specific formatting such as '每行 16-20 个中文字' and forbids spacing patterns based on Chinese typography, which effectively forces a specific language/locale convention. The file does not provide an opt-in, alternative locale mode, or any justification that this skill is limited to a Chinese-only regional workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction '任何中文字都不能交给文生图' assumes a Chinese-language workflow and reinforces a locale-specific content policy. Because the file does not clearly state that the skill is only for Chinese WeChat publishing, this reads as an undocumented language constraint rather than a justified regional requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The text states '中文一律 Microsoft YaHei' and prescribes a fixed Chinese font stack as a universal rule. Under the policy, forcing a specific language/locale without opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified as region-specific, which is not explicitly done here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly instructs use of WeChat's internal backend endpoints instead of official APIs, relying on an authenticated browser session and tokenized requests. This bypasses platform-supported integration controls such as API authorization and IP allowlisting, and normalizes automation against undocumented private interfaces that can facilitate account abuse or session hijacking if the local environment is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill recommends hooking XMLHttpRequest and fetch inside the page to capture a full 'real' request template, including a large form payload and security-sensitive fields. In context, this is effectively in-page traffic interception to harvest authenticated request bodies for later replay, which is a powerful mechanism beyond simple publishing automation and can be repurposed for unauthorized actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file describes exporting, persisting, and reinjecting cookies from a browser profile to restore authenticated sessions for several days. That materially increases credential exposure and enables session replay from local artifacts, turning the profile directory into a reusable bearer-token store that could be exfiltrated or misused by other tools or malware.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script explicitly persists authenticated WeChat public-platform session cookies to disk under the profile directory, enabling reuse of a live login state for several days. If the host is shared, compromised, backed up insecurely, or the profile directory is exposed, those cookies may permit unauthorized access to the公众号 account without re-scanning the QR code.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/gzh_login.py (reported line 333)May include surrounding context.

python
flags = 0
        if os.name == "nt":
            flags = 0x00000008 | 0x00000200  # DETACHED_PROCESS | CREATE_NEW_PROCESS_GROUP
        launched = subprocess.Popen(
            cmd, creationflags=flags, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, close_fds=True
        )
        log("已启动浏览器(PID %d),等待调试端口就绪…" % launched.pid)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script exposes a deletion capability (--delete-appmsgid) that goes beyond the stated purpose of saving articles to drafts and can remove existing drafts using the current authenticated session. In a skill executed on a user's machine with live WeChat backend cookies, this expands the blast radius from content creation to destructive content tampering if the feature is misused or invoked unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Multiple backend URLs force lang=zh_CN, which embeds a specific locale into the skill's behavior. The file does not present this as an opt-in choice or explain that the skill is intentionally limited to a China-specific environment for policy or compliance reasons.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code injects hooks into in-page networking primitives (XMLHttpRequest, fetch, sendBeacon, form.submit) to capture authenticated internal backend requests and then replays those requests with modified fields. This is effectively credential/session abuse of undocumented internal APIs, bypassing normal API controls and enabling broad action forgery within the user's authenticated publisher session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script prints the authenticated WeChat backend token directly to stdout when opening the draft editor. In this skill’s workflow, stdout may be captured by shells, terminal multiplexers, CI logs, chat transcripts, or support screenshots, which can expose a live session token that may be reused to access privileged mp.weixin.qq.com actions within the logged-in browser context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a skill for generating WeChat public-account article assets and automating draft-box upload/verification on the user's machine. The '关于作者' section adds unrelated promotional behavior and asks users to contact the author via WeChat, public account, and an external storefront URL, which goes beyond the described operational scope of the skill itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The HTML document declares lang="zh-CN", and the entire template content is written as Chinese-only instructions, which indicates a fixed language/locale choice. The file does not mention that the language is optional, configurable, or limited to a justified region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.