Back to skill

Security audit

WeChat Article Digest

Security checks for vulnerabilities and agentic risk

Overview

This skill has a clear article-digest purpose, but it asks the agent to fetch user-supplied links through a shell command and store reading history with limited safeguards.

Review before installing. Use this only in a constrained environment, prefer replacing the exec curl pipeline with web_fetch or a shell-free validated fetch, and be aware it will keep a local record of articles you send for summarization.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:15
Finding

Shell Command Injection Through User-Controlled Article URL

Content
View full analysis
]*>(.*?)', html, re.DOTALL) body = re.sub(r'<[^>]+>', '', m.group(1)).strip() if m else '' print(f'TITLE:{title}') print(f'NAME:{name}') print(f'BODY:{body}') " ``` ### Technical Analysis The Skill permits use of the `exec` tool and directs the Agent to replace the `"链接"` placeholder with a URL supplied by the user. The URL is embedded in shell command text rather than passed through a shell-free argument-array interface. Surrounding the placeholder with double quotes is not sufficient sanitization. If substitution is performed literally, an input containing a double quote followed by shell syntax can terminate the quoted argument and introduce additional shell commands. Command substitution and other shell expansion behavior may also become relevant depending on how the final command is constructed. The Skill is intended to process links matching `mp.weixin.qq.com/s/`, but the document does not impose an explicit URL-parsing, hostname-validation, character-validation, or shell-escaping requirement before invoking `exec`. Consequently, relying on the intended trigger alone does not establish a security boundary. This use of `exec` exceeds the minimum privileges required for the declared article retrieval and summarization functionality because the Skill already allows `web_fetch`, which can retrieve content without constructing a sh ...[truncated 1980 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says the skill is also used to automatically process daily forwarded article links, but it does not define precise boundaries for when this occurs. Ambiguous auto-execution conditions can cause the agent to fetch and store content without sufficiently clear user intent or consent.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill pipes data fetched from a user-supplied external URL directly into a Python process for parsing. Even though the Python code itself is static, this still creates a risky external-fetch execution path through exec, exposes the environment to attacker-controlled remote content, and lacks validation of redirects, size limits, content type, and domain enforcement; a crafted link or redirect could trigger SSRF-like access, resource exhaustion, or unintended processing of hostile content.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

用户发送 mp.weixin.qq.com/s/ 链接时:

text
curl -s -L \
  -H "User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15" \
  "链接" \
  | python3 -c "

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says the skill is also used to automatically process daily forwarded article links, but it does not define precise boundaries for when this occurs. Ambiguous auto-execution conditions can cause the agent to fetch and store content without sufficiently clear user intent or consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not clearly disclose that it will retrieve content from external URLs and append article metadata and summaries into local memory files. This weakens informed consent and can lead to privacy issues or unexpected retention of potentially sensitive reading history.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.