Back to skill

Security audit

微信公众号文章创作

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its WeChat content workflow, but it combines automatic publishing, broad credential loading, external tool execution, and unsafe shell command construction in ways users should review carefully.

Install only after reviewing the workflow and preferably running it in a sandbox or dedicated account. Use --no-auto until you have reviewed drafts, avoid untrusted URLs/search results until shell invocation is fixed, keep a dedicated env file with only the required WeChat and AI keys, and avoid forwarding real browser profiles unless you are comfortable with the WeChat session exposure.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extractor/multi_site_bridge.js:26
Finding

Shell Command Injection Through Untrusted Article URLs

Content
View full analysis
`"${u}"`); args.push('--output', `"${outputDir}"`); if (options.json) args.push('--json'); console.log(`🕷️ 调用 multi-site-extractor 抓取 ${urls.length} 篇文章...\n`); const cmd = `python3 "${extractScript}" ${args.join(' ')}`; if (options.json && !options.rewrite && !options.publish) { execSync(cmd, { stdio: 'inherit', env: process.env }); } else { execSync(cmd, { stdio: 'inherit', env: process.env }); } ``` ### Technical Analysis Article URLs are embedded directly into shell command strings passed to `execSync`. Surrounding a value with double quotes does not make it safe for a shell. Command substitutions such as `$(command)` and other shell syntax can still be evaluated inside double quotes. A quotation mark in the input can also terminate the intended argument and introduce additional commands. The vulnerable extractor bridge is used by the `links`, `search`, and `workflow` flows. Consequently, the dangerous value may originate either from a direct CLI argument or from an untrusted search result. The separate `extract` command in `main.js` constructs a shell command from every supplied URL in the same unsafe manner. This is not required for the declared extraction functionality. Node.js can invoke Python directly with an argument array without involving a shell. ### Attack Path 1. An attacker supplies a crafted URL to `links`, `extract`, or `workflow links`, or causes a poisoned URL to appear in search results. 2. The Skill passes ...[truncated 1233 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/publisher/publish_wenyan.js:91
Finding

Shell Command Injection in Formatting and Publishing Operations

Content
View full analysis
`"${a}"`).join(' ')}`; execSync(cmd, { stdio: 'inherit', env: process.env }); if (options.publish) { console.log('\n📱 推送到草稿箱...'); const pubArgs = ['--input', articlePath]; if (options.theme) pubArgs.push('--theme', options.theme); if (options.cover) pubArgs.push('--cover', options.cover); if (options.author) pubArgs.push('--author', options.author); const pubCmd = `python3 "${publishScript}" ${pubArgs.map(a => `"${a}"`).join(' ')}`; execSync(pubCmd, { stdio: 'inherit', env: process.env }); } ``` ### Technical Analysis User-controlled file paths and command options are inserted into shell command strings. Relevant values include: - Markdown file paths. - Smart-optimization output paths. - Theme and syntax-highlighting names. - Cover paths and author names. - Formatting recommendations and other CLI-derived arguments. Some values are unquoted, including `theme` and `highlight`. Other values are enclosed in double quotes, which remains unsafe because embedded quotation marks and shell substitutions can alter the command. A malicious filename alone can trigger this issue even when article content is benign. The `smart-optimize` command also publishes by default when its quality threshold i ...[truncated 1345 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/lib/openclaw_env.js:20
Finding

Excessive Loading and Propagation of Shared Environment Secrets

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/publisher/publish_wenyan.js:67
Finding

Unpinned Runtime Dependency Installation and Unsafe Supply-Chain Sources

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (95)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a comprehensive content-production and publishing tool for WeChat, including search, scraping, AI rewriting, cover generation, and publishing. The supplied code implements only a narrow subset: Markdown-level preprocessing/typesetting optimization on a local file. Its actions are limited to reading and rewriting a local article file with regex substitutions such as adding emoji to headings, bolding percentages, converting dialogue to blockquotes, adding separators, and cleaning whitespace. There is no evidence of network access, crawling, AI model usage, image/cover generation, publishing logic, or integration with external sources. While '智能排版' is partially aligned with the formatting behavior, the overall declared purpose materially overstates the capabilities of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The declared description presents a broad end-to-end content studio with search, scraping, rewriting, cover creation, layout, and publishing. The supplied code chunk performs a much narrower function: it shells out to a Python script to extract article data from a URL and returns normalized metadata/content. Multi-site article extraction is consistent with part of the description, but the primary scope of this code chunk is only scraping/normalization, not the broader workflow advertised. There are no obvious undeclared dangerous capabilities beyond extraction, but the description materially overstates what this code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents an end-user content-production tool for WeChat public accounts, with capabilities like search, scraping, AI rewriting, cover generation, and publishing. The supplied code chunk does not implement any of those user-facing functions. Instead, it is a runtime configuration utility that reads .env files from local paths and extracts credentials/settings for external services. While such configuration support could be part of a larger system, this chunk’s actual behavior is materially different from the declared purpose and includes local filesystem env loading that is not reflected in the description. Therefore this chunk is a mismatch with the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description is largely aligned with the main workflow: multi-source search, multi-site article grabbing, AI rewriting, cover generation, formatting, and publishing are all present. However, the declaration omits several materially relevant capabilities visible in the code. First, the tool does not merely assist publishing; it can automatically publish to a WeChat draft box using browser automation or wenyan-cli. Second, it executes external local scripts/skills through child_process, which is a stronger capability than the high-level description suggests. Third, it performs extensive local filesystem reads/writes to default directories under the user's home folder and processes input files. Since declared permissions are empty, these concrete capabilities/resources are undeclared. Therefore this is a mismatch, though the primary product purpose remains generally consistent with the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad content studio with search, crawling, AI rewriting, cover generation, smart typesetting, and publishing. The supplied code chunk implements only a narrow publishing function: it loads a local article file, parses minimal metadata, performs simple Markdown-to-HTML transformations, authenticates to the WeChat API, and creates/updates a draft. This is materially narrower than the declared feature set, and the missing capabilities are central to the description rather than incidental. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述的是一个覆盖内容搜索、抓取、改写、封面生成和排版发布的完整工作室工具;但该代码片段实际只涉及发布侧的浏览器自动化/半自动化辅助。它通过调用 uvx browser-use 打开微信公众号后台,提示用户手动完成文章创建、AI 配图和发布,并读取本地 Markdown 文件提取标题。代码中没有实现搜索、抓取、AI 改写或智能排版等声明中的关键能力。虽然“封面生成、发布”与描述有部分重合,但这里也主要是打开后台并提示人工操作,能力范围明显窄于声明,因此构成描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

描述将该技能定位为覆盖搜索、抓取、改写、封面生成、排版发布的完整内容工作室,而提供的代码块实际功能范围明显更窄,主要是将现有 Markdown 文章发布到微信公众号。代码会规范化 Markdown、补充 frontmatter、检查本地封面文件、安装并调用 wenyan-cli,以及打开微信公众平台后台进行人工发布辅助。这些行为与“智能排版发布”部分基本一致,但与声明中的搜索、抓取、AI 改写、封面生成等核心能力不符。虽然未发现明显越权或恶意的额外能力,但描述对代码实际能力有明显夸大,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad end-to-end content production and publishing studio for WeChat official accounts. However, the supplied code chunk is narrowly focused on search aggregation. It performs external searches across several sources, including WeChat pages, general site-specific Brave searches, Hacker News, GitHub Trending, Product Hunt, and arXiv, then deduplicates and summarizes the results. It does not fetch full articles from discovered links, does not rewrite content with AI, does not generate covers, does not format/layout content, and does not publish anything. While 'multi-source authoritative search' is consistent with part of the description, the overall declared purpose materially overstates this code chunk’s behavior and includes several major capabilities absent from the implementation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a broad end-to-end WeChat content workflow tool, including multi-source authoritative search, article scraping, AI rewriting, cover generation, and publishing. The supplied code chunk is much narrower: it builds search query strings with optional site restrictions (including WeChat domain targeting) and returns them for an external agent to run. It does not fetch search results directly, scrape articles, process content, generate media, or publish anything. This is a material description-behavior mismatch because the actual code’s primary purpose is only a search adapter, not a full content studio.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The documented .env lookup order includes user home directories and an override path, meaning the skill is intended to read local credential stores containing API keys and WeChat secrets. In an agent-executed skill, broad credential discovery increases the blast radius if the skill or a dependency is compromised, because sensitive tokens can be accessed from multiple standard locations.

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
| 联网搜索代理 | `HTTPS_PROXY` / `HTTP_PROXY` | 访问 Brave/GitHub 等;未设时默认 `http://127.0.0.1:7890` |
| Brave 请求间隔 | `BRAVE_SEARCH_MIN_INTERVAL_MS` | 两次 Brave 请求最小间隔(毫秒),默认 `3200`,遇 429 可调大 |

**.env 查找顺序:**
1. `OPENCLAW_ENV_FILE`(若设置)
2. 技能根目录 `.env`
3. `~/.openclaw/.env`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 256)May include surrounding context.

md
1. **不调用** `node scripts/main.js search` 命令

Known Vulnerable Dependency: axios==1.14.0 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
94% confidence
Finding

The lockfile pins axios 1.14.0, which the scanner reports as having multiple known advisories including SSRF/proxy-bypass and prototype-pollution-related request/credential compromise issues. In this skill's context—multi-source web search, article fetching, and use of proxy agents—an HTTP client weakness is materially relevant because untrusted URLs, redirects, and proxy behavior are core functionality.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
80% confidence
Finding

form-data 4.0.5 is reported vulnerable to CRLF injection through unescaped multipart field names and filenames. This becomes relevant if the skill uploads generated media, cover images, or scraped assets using multipart requests with attacker-influenced metadata, potentially enabling header/body injection against downstream services.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==7.24.6 — 12 advisory(ies): CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-13697 (undici vulnerable to cross-user information disclosure and parse-time crash via ); CVE-2026-16728 (undici vulnerable to downstream response desynchronization via retry interceptor) +9 more

High
Category
Supply Chain
Confidence
88% confidence
Finding

undici 7.24.6 is flagged for multiple HTTP parsing, queue poisoning, desynchronization, and information disclosure issues. Because this skill performs remote article retrieval and HTML parsing, a vulnerable HTTP stack can expose fetched content, mix responses between requests, or make the agent unreliable or exploitable when interacting with malicious servers.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.14.0 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The static finding indicates axios 1.14.0 is within the allowed dependency range and is associated with multiple advisories, including SSRF-related NO_PROXY bypass and prototype-pollution-based MITM/credential-theft scenarios. This skill’s purpose—multi-source search, article fetching, and publishing—makes HTTP request integrity central, so a vulnerable HTTP client substantially increases risk to fetched content, credentials, and internal network access.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The module reads environment variables and loads credentials via loadOpenClawEnv/resolveDashScopeKey, but the finding indicates this capability is not covered by declared permissions. In an agent-skill context, undeclared access to env can expose secrets or broaden trust boundaries without user awareness, especially since the script also passes the API key into a spawned subprocess.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/image/generate_cover.js (reported line 212)May include surrounding context.

js
prompt += '\n要求:高清,专业,吸引眼球,适合做封面,无文字或少文字,16:9 比例';
  
  return prompt;
}

/**

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lib/openclaw_env.js (reported line 28)May include surrounding context.

js
files.push(process.env.OPENCLAW_ENV_FILE);
  }

  files.push(path.join(skillRoot, '.env'));

  const home = process.env.HOME || process.env.USERPROFILE || '';
  if (home) {

Credential Access

High
Category
Privilege Escalation
Confidence
71% confidence
Finding

The code automatically reads ~/.openclaw/.env from the user's home directory and imports any variables found there into the current process without confirmation or allowlisting. In a skill ecosystem, this broad implicit trust can expose unrelated secrets to downstream code in the skill, increasing the blast radius if the skill later logs, forwards, or misuses environment variables.

Content

Scanner excerpt · scripts/lib/openclaw_env.js (reported line 32)May include surrounding context.

js
const home = process.env.HOME || process.env.USERPROFILE || '';
  if (home) {
    files.push(path.join(home, '.openclaw', '.env'));
    files.push(path.join(home, '.workbuddy', '.env'));
  }

Credential Access

High
Category
Privilege Escalation
Confidence
71% confidence
Finding

The code also auto-loads ~/.workbuddy/.env, which may contain credentials unrelated to this skill, and merges them into process.env without user awareness or scoping. In the context of a content studio skill that may interact with external services, this increases the chance that powerful tokens become accessible to more code paths than intended.

Content

Scanner excerpt · scripts/lib/openclaw_env.js (reported line 33)May include surrounding context.

js
const home = process.env.HOME || process.env.USERPROFILE || '';
  if (home) {
    files.push(path.join(home, '.openclaw', '.env'));
    files.push(path.join(home, '.workbuddy', '.env'));
  }

  const seen = new Set();

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/smart-optimize.js (reported line 252)May include surrounding context.

js
});
    
    this.rules.push(...rules);
    return rules;
  }

  /**

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/smart-optimize.js (reported line 339)May include surrounding context.

js
});
    
    this.rules.push(...rules);
    return rules;
  }

  /**

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/smart-optimize.js (reported line 389)May include surrounding context.

js
});
    
    this.rules.push(...rules);
    return rules;
  }

  /**

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/smart-optimize.js (reported line 423)May include surrounding context.

js
});
    
    this.rules.push(...rules);
    return rules;
  }

  /**

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The combination of Write permission and a fixed home-directory output location enables durable storage of generated and scraped materials. This is not necessarily malicious, but it does create privacy and retention risk if the skill handles sensitive drafts, proprietary source text, or publication metadata without user awareness.

Content

Scanner excerpt · SKILL.md (reported line 6)May include surrounding context.

md
description: 微信公众号内容工作室 — 支持多来源权威搜索、多站点文章抓取、AI 改写、封面生成、智能排版发布的一站式工具
author: 模型猎人
version: 2.2.0
allowed-tools: Bash,Read,Write
---

# 微信公众号内容工作室 (WeChat Content Studio)

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/extractor/multi_site_bridge.js:26

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/image/generate_cover.js:133

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/main.js:1024

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/publisher/publish_browser.js:40

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/publisher/publish_wenyan.js:68

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/smart-optimize.js:730