Back to skill

Security audit

wewe-rss WeChat Export

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real WeChat feed exporter, but it needs Review because it can fetch arbitrary feed and image URLs from the agent host without private-network or size limits.

Install only if you trust the feed sources and are comfortable with the agent host making outbound HTTP(S) requests and writing exported files locally. Avoid running it on sensitive internal networks or against untrusted feeds unless the runtime has network controls that block private, link-local, loopback, and metadata-service addresses, plus disk and memory limits.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/export-feed-single-pages.mjs:174
Finding

Unrestricted Outbound Requests Enable Server-Side Request Forgery

Content
View full analysis
&2 exit 1 fi ``` ```js const buildPageUrl = (baseUrl, page) => { const url = new URL(baseUrl); url.searchParams.set('limit', String(batchSize)); url.searchParams.set('page', String(page)); return url.toString(); }; const curlJson = (url) => { const stdout = execFileSync( 'curl', [ '--http1.1', '--compressed', '--silent', '--show-error', '--location', '--max-time', String(CURL_TIMEOUT_SECONDS), '--user-agent', 'Mozilla/5.0 Claude Export Script', '--header', 'accept: application/json,text/plain,*/*', url, ], { encoding: 'utf8', maxBuffer: 64 * 1024 * 1024 }, ); return JSON.parse(stdout); }; ``` ```js const normalizeUrl = (value = '', baseUrl = 'https://mp.weixin.qq.com/') => { const trimmed = String(value || '').trim(); if (!trimmed) return ''; if (trimmed.startsWith('data:')) return trimmed; try { const url = new URL(trimmed, baseUrl); if (!['http:', 'https:'].includes(url.protocol)) { return ''; } return url.toString(); } catch { return ''; } }; ``` ```js const downloadBinary = async (url) => { const response = await fetch(url, { headers: { 'user-agent': 'Mozilla/5.0 Claude Export Script', accept: 'image/*,*/*;q=0.8', referer: 'https://mp.weixin.qq.com/', }, signal: AbortSignal.timeout(IMAGE_TIMEOUT_MS), }); if (!response.ok) { throw new Error(`Image fetch failed: ${response.status} ${response.statusText}`); } const arrayBuffer = await response.arrayBuffer(); return { buffer: Buffer.from(arrayBuffer) ...[truncated 2381 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/export-feed-single-pages.mjs:558
Finding

Unbounded Image Downloads Can Exhaust Memory and Disk Space

Content
View full analysis
{ const response = await fetch(url, { headers: { 'user-agent': 'Mozilla/5.0 Claude Export Script', accept: 'image/*,*/*;q=0.8', referer: 'https://mp.weixin.qq.com/', }, signal: AbortSignal.timeout(IMAGE_TIMEOUT_MS), }); if (!response.ok) { throw new Error(`Image fetch failed: ${response.status} ${response.statusText}`); } const arrayBuffer = await response.arrayBuffer(); return { buffer: Buffer.from(arrayBuffer), extension: guessExtension(url, response.headers.get('content-type') || ''), }; }; ``` ### Technical Analysis The exporter buffers each response body in its entirety through `response.arrayBuffer()` before writing it to disk. It does not enforce a maximum `Content-Length`, count streamed bytes, restrict the number of images per article, or impose an aggregate download quota. The 30-second timeout limits download duration but not response size. A server on a sufficiently fast connection can return a very large body within that period. The response is first represented as an `ArrayBuffer` and then converted into a Node.js `Buffer`, which may temporarily increase memory pressure further. The response is also accepted based on request success without verifying that the payload is a valid image. A malicious server can therefore provide arbitrary large binary data under a misleading image content type. ### Attack Path 1. An attacker publishes or controls a JSON feed processed by the Skill. 2. An article in the feed contains one or more attacker-controlled image URLs. 3. The image endpoint returns a very large response or numerous moderately large responses. 4. The exporter reads each complete response into memory using `arrayBuffer()`. 5. The process exper ...[truncated 680 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · INSTALL.md (reported line 13)May include surrounding context.

openclaw gateway status node --version pandoc --version curl --version python3 --version

text

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing instructions exclusively in Chinese, including setup, publishing steps, and cautions. Under the language/locale policy, forcing a specific language without user opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to invoke shell scripts (bash <skill_dir>/scripts/run-export-feed.sh ...) and declares operational behavior around local command execution, but it does not define any permissions or allowed-tools scope. That omission weakens least-privilege controls and can allow broader-than-necessary shell access when the skill is used, especially because it processes user-supplied URLs and output paths.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script invokes local executables via execFileSync to fetch feed data with curl and convert documents with pandoc. While document conversion itself fits the export purpose, implementing it by spawning arbitrary system binaries is a broader capability than the manifest describes and introduces dependence on host-level command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script retrieves remote JSON via curl and later writes derived HTML, Markdown, DOCX, and summary files to disk, but the only user-facing messages are usage/progress logs rather than a warning that remote content will be downloaded and saved locally. For a code file, network retrieval plus file creation should have some explicit disclosure when not otherwise documented in the file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script downloads arbitrary remote image URLs extracted from feed/article content and writes them to disk. Because the feed content is untrusted, this creates an SSRF-style outbound fetch surface and can be abused to force connections to attacker-controlled or internal network hosts, or to consume bandwidth/storage during export.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script fetches image binaries from external URLs and stores them under an assets directory, which is a network-plus-file-write operation affecting local data. Although later progress and summary output exist, there is no explicit disclosure near this behavior that images from article content will be fetched and persisted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

该 markdown 文件适用 SQP-2。L34-L38 的安装步骤会创建目录、解压文件、修改可执行权限并执行 openclaw gateway restart,这些操作会影响本地环境和正在运行的服务,但文档未明确提醒用户这些命令会写入工作区并重启网关。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

L65-L73 的验证命令会运行导出脚本并生成 docx/zip 等输出,且 L78 说明未传 output_dir 时会默认写入当前工作目录下的 export/。文档虽描述了默认路径,但缺少显式的用户提醒,未直接告知该验证步骤会产生本地文件输出。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly instructs users to fetch remote feeds, write output files, and optionally create ZIP archives, but it does not clearly warn about those side effects or the trust assumptions involved. In a skill ecosystem, this can mislead users into running network and filesystem-modifying operations without understanding that untrusted feed content may be downloaded, transformed, and stored locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

Natural-language output is forced to use the zh-CN locale and Asia/Shanghai timezone for published date display, which is a locale policy concern under the specified rules. The file does not offer user opt-in or configuration for alternative language/locale settings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The generated document sets unconditionally, which enforces a specific language/locale in output artifacts. Under the policy rules, this should either be user-selectable or clearly justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/export-feed-single-pages.mjs:301