Back to skill

Security audit

微信公众号阅读器

Security checks for vulnerabilities and agentic risk

Overview

This skill is advertised as a WeChat article reader, but the package also contains broader browser scraping, search, Notion/Zhihu tooling, stealth behavior, and local capture features that are not fully scoped or disclosed.

Review this skill before installing. It may be usable for public WeChat article extraction, but the package includes broader scraping/debug utilities, stealth automation, arbitrary URL handling, and local screenshot/HTML retention. Install only in an isolated environment, avoid private or internal URLs, and prefer a version that removes unrelated scripts, pins dependencies, and enforces a strict mp.weixin.qq.com allowlist.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
extract_generic.py:114
Finding

Arbitrary URL Navigation Enables Server-Side Request Forgery

Content
View full analysis
1 else 'https://www.notion.so/Playwright-CLI-Claude-Code-1bd25b1f28234a45b69b3f5d75a595c1' result = extract_notion(url) print(json.dumps(result, ensure_ascii=False, indent=2)) ``` `notion_screenshot.py:18-21, 47-50`: ```python try: print(f"正在访问: {url}") # Notion 可能需要更长的加载时间 page.goto(url, wait_until='domcontentloaded', timeout=60000) if __name__ == '__main__': url = sys.argv[1] if len(sys.argv) > 1 else 'https://www.notion.so/Playwrig ...[truncated 2859 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
extract.py:64
Finding

Incomplete SSRF Validation in the Primary Extractor

Content
View full analysis
{resolved_ip}" except socket.gaierror: # DNS 解析失败,可能是内网域名或无效域名 return False, f"无法解析域名: {hostname}" return True, None ``` `extract.py:108-113`: ```python try: # 访问页面并等待加载 page.goto(url, wait_until='networkidle', timeout=30000) # 等待内容加载 page.wait_for_selector('#js_content, .rich_media_content', timeout=10000) ``` `extract.py:242-253`: ```python url = sys.argv[1] # 验证 URL 安全性 is_valid, error_msg = validate_url(url) if not is_valid: print(json.dumps({ 'success': False, 'error': f'URL 验证失败: {error_msg}' }, ensure_ascii=False)) sys.exit(1) result = extract_article(url) ``` ### Technical Analysis The validator checks only the first address returned by `socket.getaddrinfo()`. A hostname can have multiple IPv4 and IPv6 results, and a safe first result does not guarantee that all possible destinations are safe. Address safety is determined using string prefixes rather than semantic IP classification. This omits important non-public ranges, including IPv4 link-local addresses such as `169.254.0.0/16`, IPv6 unique-local addresses, IPv6 link-local addresses, multicast ranges, and reserved ranges. There is also a time-of-check/time-of-use gap: Python resolves the ...[truncated 1533 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
extract_stealth.py:55
Finding

Chromium Web Security and Site Isolation Are Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
debug.py:12
Finding

Predictable Shared Paths Are Used for Raw HTML and Page Screenshots

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Python Dependencies and Browser Installation Are Not Reproducibly Pinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述强调的是“微信公众号文章内容提取”和“结构化输出”。但实际代码并未实现针对 mp.weixin.qq.com 的专门提取逻辑,也没有抽取文章正文、作者、发布时间等结构化字段。相反,它主要是一个调试工具:打开页面、等待、保存截图、导出 HTML,并打印若干通用选择器命中情况。此外,默认 URL 指向知乎专栏,保存文件名也为 debug_zhihu,说明实际用途更接近通用网页/知乎页面调试分析,而不是微信公众号文章抓取器。因此描述与代码行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

描述将该技能限定为“提取微信公众号文章内容”,触发词也聚焦微信文章;但代码明显是多平台通用文章提取器。文件注释写明支持微信公众号、知乎专栏、简书、CSDN 等,实际分支中除微信外还专门实现了知乎提取逻辑,并对其他站点执行通用正文抽取。其主要能力不是仅限微信公众号,而是对任意给定文章 URL 进行抓取、渲染和结构化提取。因此描述未准确覆盖实际行为,属于能力范围明显大于声明的描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该代码文件名、模块注释、核心函数名均明确指向 Notion 内容提取(extract_notion / 提取 Notion 页面内容)。实现上通过 Playwright 打开任意 URL,等待页面加载后用 BeautifulSoup 按 Notion 常见结构选择器(如 [data-block-id]、.notion-page-content)提取文本,没有任何微信公众号页面特定逻辑,也没有针对 mp.weixin.qq.com 的 DOM 结构、反爬流程或文章字段解析。因此其主要目的与声明存在明显且实质性的偏差。虽然从技术上它也能对某些普通网页做通用文本提取,但其实现重点和默认目标都不是微信公众号文章。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是“微信公众号文章内容提取”,触发词也集中在微信生态(微信公众号、mp.weixin.qq.com、微信文章)。但代码中的实现与微信文章无关:函数名和注释多次表明目标是“知乎”,提取逻辑完全依赖知乎页面选择器(如 h1.Post-Title、.AuthorInfo-name、.Post-RichTextContainer),并且在抓取前固定访问 https://www.zhihu.com 建立会话。这说明其主要目的并非通用或微信文章提取,而是针对知乎的反爬绕过与内容抓取。此外,代码还包含 stealth 模式、禁用自动化特征、保存截图等未在声明中体现的重要行为。因此,描述与实际行为存在明显且实质性的不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是“微信公众号文章抓取与结构化提取”能力,但实际代码并未实现公众号文章正文解析、内容抽取、结构化输出等功能。相反,它的核心行为是通过浏览器访问指定 URL,对页面截图并读取标题,且注释和默认 URL 都明确指向 Notion 页面调试。这说明其主要用途与声明严重不符,访问资源类型、输出形式和触发场景也都不一致,因此应判定为明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心用途是抓取和结构化输出微信公众号文章内容,但代码实际上是一个通用网页滚动抓取/截图脚本,文件名、注释和默认 URL 都明确指向 Notion 页面。它没有体现对 mp.weixin.qq.com 的专门适配、公众号文章特有结构解析或与声明触发词一致的限制,反而增加了本地截图保存这一未声明能力。因此其主要用途与声明存在明显偏差。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心能力是对微信公众号文章链接(mp.weixin.qq.com)进行内容抓取和结构化提取。但代码中没有任何针对微信文章链接的处理逻辑,没有识别或请求 mp.weixin.qq.com 页面,也没有抽取文章标题、作者、发布时间、正文等文章内容。相反,代码通过 Playwright 打开 Google 搜索,构造搜索 URL,抓取并解析 Google 搜索结果页,返回标题、URL、摘要。这属于“搜索其他来源/网页搜索”能力,和声明的主要用途存在明显偏差,属于实质性描述与行为不一致。

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill performs outbound network access through Playwright page loading and DNS resolution, but the static finding indicates this capability is not declared in permissions. Undeclared network capability is dangerous because it weakens platform trust boundaries, can surprise deployers, and increases the impact of SSRF or unintended external access if the skill is invoked on attacker-controlled URLs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation fetches and extracts content from arbitrary Notion URLs even though the skill metadata claims it handles WeChat public article links. This mismatch is dangerous because it expands the skill's effective data-access scope beyond what users and reviewers expect, enabling unintended scraping of third-party content and bypassing policy or trust assumptions tied to the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file’s purpose and implementation materially diverge from the advertised skill. Instead of a WeChat article reader, it is a generic/Zhihu-oriented scraper that explicitly mentions bypassing anti-crawling protections, which is a strong indicator of undeclared capability and raises trust and abuse concerns.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code intentionally applies stealth techniques and launches Chromium with flags such as '--disable-web-security' and automation-evasion settings, despite the stated benign purpose of reading public articles. This expands the skill from simple content extraction into anti-detection scraping behavior that can facilitate policy evasion and unauthorized collection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file’s behavior materially contradicts the declared skill purpose: instead of extracting WeChat article content, it launches a browser and screenshots an arbitrary attacker-supplied URL. In an agent skill context, this kind of scope mismatch is dangerous because it can be used as a covert web-fetching/browser automation primitive, enabling unintended access to external pages, screenshot capture of sensitive content, and bypass of user expectations or policy controls.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file’s stated behavior and default URL target generic Notion pages, which directly contradicts the skill manifest claiming WeChat article extraction. This scope mismatch is dangerous because users and orchestration systems may grant network or content-handling trust based on the manifest, while the code actually operates on unrelated third-party content, creating deceptive capability drift.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring explicitly describes scrolling and capturing Notion page content, which conflicts with the identity of a WeChat-reader skill. In security-sensitive agent ecosystems, this kind of identity mismatch is dangerous because it can disguise actual capabilities, mislead reviewers, and enable unauthorized collection from unrelated web targets.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code performs unrestricted Google search automation for arbitrary queries rather than limiting itself to extracting content from mp.weixin.qq.com articles as declared by the skill manifest. This creates a capability mismatch that can be abused for unintended web reconnaissance, data gathering, or policy bypass under the guise of a WeChat-reader skill, making the actual behavior more dangerous in context than a simple implementation bug.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The triggers include broad terms like '微信公众号' and '微信文章', which can activate the skill during ordinary discussion rather than an explicit request to fetch a URL. In a skill that can access external content via browser automation, overbroad triggering increases the chance of unintended network access, data handling, or misuse in contexts the user did not intend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

User-facing messages and documentation strings in this file are written only in Chinese, which imposes a language choice on users without opt-in. The file does not indicate that the skill is intentionally region-specific or provide any mechanism to select another language.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This debug script persists a full-page screenshot and complete HTML of arbitrary visited URLs to local disk, which can capture sensitive article content, embedded tokens, reader-specific data, or private material beyond the skill's stated purpose of extracting structured WeChat article content. Because the URL is attacker- or user-controlled and the output path defaults to /tmp, the skill creates unnecessary local data retention and broadens exposure if other local users, processes, or logs can access those files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Writing raw HTML from visited pages directly to disk creates a local data-capture risk without notice or consent, especially since the page may contain personal data, authentication-linked content, tracking parameters, or hidden fields not needed for article extraction. In the context of a content-reading skill, silently storing the full document exceeds the minimum data necessary and increases the blast radius of any host compromise or cross-user file exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file-level docstring is entirely in Chinese and presents the skill as a WeChat article extractor with no indication that another language is supported or that the Chinese-only behavior is optional. The policy specifically calls for flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · extract.py (reported line 161)May include surrounding context.

python
metadata['source_url'] = url
            
            # 提取时间戳
            metadata['extracted_at'] = __import__('datetime').datetime.now().isoformat()
            
            # ========== 提取正文内容 ==========
            content = ""

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

清单描述将技能定位为“提取微信公众号文章内容”,触发词也仅围绕微信公众号,但文件头注释明确声明支持知乎、简书、CSDN 等,且后续代码实现了知乎专用提取和通用网页提取逻辑。这表明实际行为明显比声明范围更广,不只是实现微信公众号文章抓取。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code includes natural-language descriptions and user-facing messages only in Chinese, and there is no indication that the skill is limited to Chinese-speaking users or that language selection is configurable. That can violate a language/locale policy requiring user choice or explicit justification for a fixed locale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function accepts any user-supplied URL and drives a headless browser to fetch and render it, despite the stated skill scope implying only WeChat article links. In an agent environment, this can enable SSRF-style access to internal services, local network endpoints, or other unintended destinations through the browser runtime.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file and function docstrings explicitly state that the code extracts Notion page content, contradicting the declared purpose of a WeChat article reader. In security-sensitive agent ecosystems, this kind of documentation mismatch is risky because it signals hidden or undisclosed capability and makes review, user consent, and policy enforcement less reliable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.