Back to skill

Security audit

报告双通道智能推送

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to send reports to WeChat-style push notifications and QQ Mail, but it handles a PushPlus token and report summaries over plaintext HTTP and has overly broad invocation wording.

Install only if you are comfortable sending report summaries to PushPlus and full report text through QQ Mail. Before using it, change the PushPlus endpoint to HTTPS, rotate any PushPlus token previously used with this version, narrow the trigger wording or require explicit confirmation, verify the recipient address, and fix the script filename mismatch and dependency installation pinning.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ush_report.py:38
Finding

PushPlus credential and report summary transmitted over plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/ush_report.py, lines 38-46
Vulnerability Type: Plaintext transmission of sensitive data
Risk Level: High

Vulnerable Code:

python
url = 'http://www.pushplus.plus/send'
data = {
    "token": token,
    "title": title,
    "content": summary,
    "template": "txt"
}
try:
    response = requests.post(url, json=data, timeout=10)

Technical Analysis

The script submits the WECHAT_PUSH_KEY, report title, and report summary to PushPlus through an unencrypted HTTP connection. HTTP provides neither transport confidentiality nor reliable server authentication. Any attacker capable of observing or modifying traffic between the host and the remote service can inspect the request body or tamper with it.

The exposed token may function as a reusable authorization credential for sending notifications through the associated PushPlus account. The report title and summary may also contain confidential business, financial, or research information.

Attack Path

  1. A user invokes the skill to push a report through the WeChat channel.
  2. The script reads WECHAT_PUSH_KEY from the environment and places it in the JSON request body.
  3. The script sends the request to http://www.pushplus.plus/send.
  4. An attacker with a suitable network position, such as a compromised gateway, hostile access point, or upstream network observer, intercepts the plaintext request.
  5. The attacker extracts the PushPlus token and report data or modifies the notification in transit.
  6. If the token remains valid and reusable, the attacker can use it to submit unauthorized notifications.

Impact Assessment

Successful exploitation can disclose the PushPlus authorization token, report title, and report summary. An attacker may be able to send unauthorized or misleading notifications to the token owner. This issue does not directly expose the QQ Mail authorization code ...[truncated 103 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the endpoint with https://www.pushplus.plus/send.
  • Keep TLS certificate verification enabled and do not use verify=False.
  • Explicitly reject redirects from HTTPS to HTTP before transmitting credentials.
  • Consider restricting redirects entirely unless required by the documented API.
  • Rotate the existing WECHAT_PUSH_KEY because it may already have traversed untrusted networks in plaintext.
  • Avoid including secrets in exception messages, logs, or diagnostic output.
  • Add an automated test that verifies all credential-bearing endpoints use HTTPS.

T08 · Insecure Dependencies

Warning
Location
skill.md:22
Finding

Dependency installation metadata bypasses the pinned requirements file

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 22-26; related declaration in requirements.txt, line 1
Vulnerability Type: Unconstrained and non-hash-verified dependency installation
Risk Level: Medium

Vulnerable Code:

yaml
install:
  - id: "requests"
    kind: "command"
    command: "pip3 install requests"
    bins: ["python3"]

The separate requirements file contains:

text
requests==2.31.0

Technical Analysis

The installation command in the skill metadata installs requests without a version constraint and does not use the separately pinned requirements.txt. Consequently, the package version actually installed through the documented metadata path is determined at installation time.

Neither installation path uses package hashes. The command also relies on the operator's configured package index without declaring an approved index. These conditions weaken reproducibility and supply-chain integrity. If dependency resolution or the configured index is compromised, installation can retrieve unintended package artifacts. Python package installation may execute package build or installation logic with the privileges of the user running pip3.

Attack Path

  1. The skill installation process executes pip3 install requests as declared in skill.md.
  2. Pip resolves the package dynamically using the environment's configured index and trust settings rather than the pinned declaration in requirements.txt.
  3. An attacker who can compromise or influence that package source, index configuration, name resolution, or returned package artifact supplies an unintended distribution.
  4. Because no expected artifact hash is enforced, the installer has no project-level integrity check to reject the substituted artifact.
  5. Malicious build or installation logic executes with the privileges of the account performing the installation.

This path requires prior influence over the ...[truncated 542 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the unconstrained metadata command with installation from a locked requirements file:
    text
    pip3 install --require-hashes -r requirements.txt
    
  • Pin all direct and transitive dependencies to reviewed versions.
  • Add SHA-256 hashes for every permitted distribution artifact.
  • Use an explicitly approved HTTPS package index and prevent fallback to untrusted indexes.
  • Keep the metadata installation command and requirements.txt synchronized so both installation paths resolve identical artifacts.
  • Run dependency installation in an isolated virtual environment under a non-privileged account.
  • Periodically update and security-review the lock file rather than allowing implicit installation of the latest release.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Tainted flow: 'data' from os.environ.get (line 41, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The script sends a secret-derived token from an environment variable to an external network endpoint as part of the HTTP request body. While this is functionally required for the PushPlus API, it is still an external transmission of sensitive authentication material and report metadata to a third party; if the endpoint is intercepted or changed, the token and pushed content could be exposed or abused.

Content

Scanner excerpt · scripts/ush_report.py (reported line 48)May include surrounding context.

python
"template": "txt"
    }
    try:
        response = requests.post(url, json=data, timeout=10)
        if response.status_code == 200:
            return True, "成功"
        return False, f"HTTP状态码异常: {response.status_code}"

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

代码的核心功能与描述大体一致:发送微信摘要和QQ邮箱全文,且微信摘要限制为100字以内、支持分别或同时推送两个渠道。不过,描述声称由“说‘推送报告’时触发”,而实际代码只是一个命令行脚本,没有任何语音、关键词监听或触发器实现,这是明显的不一致。此外,所谓“微信推送”实际是调用 pushplus.plus 的第三方推送服务,虽然最终用途可能是推送到微信,但资源访问层面与直接微信接口并不完全一致。总体来看,主功能基本匹配,但触发机制存在实质性描述不符,因此应判定为 mismatch。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: requests==2.31.0 — 6 advisory(ies): CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi); CVE-2026-25645 (Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility func) +3 more

Medium
Category
Supply Chain
Confidence
96% confidence
Finding

The file pins requests to version 2.31.0, which is reported by the scanner as having multiple published advisories. Using a dependency with known security issues is a real supply-chain risk because the skill likely performs outbound network operations to push reports to WeChat and QQ Mail, increasing exposure to URL handling, session, and transport-related bugs in the HTTP client.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script emails full report contents using configured mailbox credentials without warning or consent logic in the code. In this skill's context, that means potentially sensitive reports are exported off-platform to a recipient address, creating a realistic confidentiality risk if the destination is wrong, compromised, or unauthorized.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script transmits report summaries to an external push service without any built-in disclosure, confirmation, or data-classification check. In an agent skill context, reports may contain sensitive internal analysis, so silent exfiltration to a third-party notification service increases the risk of accidental data leakage.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The script performs an outbound network transmission of report summary data to an external service. In a reporting skill, this behavior is expected, but it still constitutes a genuine data egress path that can leak sensitive information if content is not screened and transport is not properly secured.

Content

Scanner excerpt · scripts/ush_report.py (reported line 48)May include surrounding context.

python
"template": "txt"
    }
    try:
        response = requests.post(url, json=data, timeout=10)
        if response.status_code == 200:
            return True, "成功"
        return False, f"HTTP状态码异常: {response.status_code}"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases include very generic everyday expressions such as '通知我' and '把报告发给我', which can cause the skill to activate in contexts where the user did not specifically intend external delivery. Because this skill sends content to external channels (WeChat and email), accidental invocation can lead to unintended data disclosure or spammy outbound actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script hard-codes Chinese-language user-facing strings such as error messages, labels, and argument descriptions, with no option to select another language. That creates a locale/language constraint not offered as a user choice and is a policy issue under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language description is entirely in Chinese and the required output template later in the file also prescribes Chinese summary labels, which indicates a fixed language expectation. There is no indication that users may choose another language or that the Chinese-only behavior is a documented, justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions require the agent to generate the summary using fixed Chinese headings such as "结论", "待办", and "⚠️", which enforces a specific language/locale. Because no user opt-in or justified locale limitation is provided, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.