Back to skill

Security audit

wjx-cli-use

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Wenjuanxing CLI skill, but its installer can globally install mutable code, use sudo, overwrite agent skill files, and handle API credentials with insufficient safeguards.

Review before installing. Prefer a pinned, reviewed wjx-cli version; avoid sudo/global installs when possible; do not run curl-to-bash setup commands; confirm any skill-file overwrite before accepting it; treat API keys and generated SSO URLs as secrets; and require explicit confirmation before delete, clear, account, admin, department, tag, or response-submission actions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/install-nodejs.md:20
Finding

Remote installation scripts are executed directly through shell pipelines

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:18
Finding

Mutable npm packages are installed globally and can forcibly replace agent Skill files

Content
View full analysis
/dev/null && sudo npm install -g wjx-cli@latest; then return 0 fi print_error "wjx-cli 升级失败" return 1 } ``` The setup flow also installs the Skill through the newly downloaded executable: ```bash install_core_skill() { print_info "安装 wjx-cli-use 技能..." local root root="$(resolve_install_root)" if wjx skill install --force --target-dir "$root"; then print_success "wjx-cli-use 技能已安装" return 0 fi print_error "wjx-cli-use 技能安装失败" return 1 } ``` The fallback guidance includes another remote execution path through npm: ```bash echo "或使用 npx 免安装运行:" echo " npx wjx-cli@${MIN_WJX_CLI_VERSION} survey list" ``` ### Technical Analysis The `@latest` npm tag is mutable. It does not identify the exact package version reviewed with this Skill, and the package contents are not included in the audited project. Consequently, the effective code executed during installation can change after this audit. npm packages may execute lifecycle scripts during installation. A compromised package release or publisher account could therefore run arbitrary code during the global installation. The fallback to `sudo npm install -g` substantially increases the consequence by allowing package installation behavior to execute with elevated privileges. After installation, the downloaded `wjx` executable runs `wjx skill install --force`. This delegat ...[truncated 1918 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
setup.sh:257
Finding

API keys may be exposed through process arguments and transmitted to plaintext custom endpoints

Content
View full analysis
``` ```bash wjx init --api-key --base-url https://<域名> ``` From `setup.sh`, the supplied base URL accepts both HTTP and HTTPS: ```bash normalize_base_url() { local value value="$(trim_whitespace "${1:-$DEFAULT_WJX_BASE_URL}")" value="${value:-$DEFAULT_WJX_BASE_URL}" while [[ "$value" == */ ]]; do value="${value%/}"; done if [[ "$value" != http://* && "$value" != https://* ]]; then value="https://$value" fi if [[ "$value" == */openapi/* ]]; then value="${value%%/openapi/*}" fi printf '%s' "$value" } ``` The API key is then supplied as a command-line argument: ```bash configure_cli() { print_info "Step 4/5: 配置 wjx-cli..." if has_nonblank "${WJX_API_KEY:-}"; then local args=(--api-key "$WJX_API_KEY" --base-url "$WJX_BASE_URL" --no-install-skill) if has_nonblank "${WJX_CORP_ID:-}"; then args+=(--corp-id "$WJX_CORP_ID") fi wjx init "${args[@]}" return $? fi echo "" echo " 请将刚才复制的 API Key 粘贴到下方:" echo "" wjx init --no-install-skill } ``` ### Technical Analysis Secrets passed in command-line arguments may be visible to process-monitoring tools, audit systems, diagnostic collectors, shell tracing, or other users with sufficient local process-inspection permissions. The script correctly quotes the API key, which prevents ordinary shell word splitting, but quoting does not prevent exposure through process metadata. The URL normalization function defaults to HTTPS only when no scheme is supplied. An explicitly supplied `http://` URL is preserved and subsequently passed to `wjx init`. If the CLI communicates w ...[truncated 1727 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is an end-user guide/skill for operating wjx-cli survey functions. The supplied code does not implement survey operations, response querying, exporting, analysis, or account/contact management. Instead, it is a build/packaging utility for distributing the skill itself. This is a materially different primary purpose, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

Piping directly into bash is a classic unsafe chaining pattern because it executes remote content immediately without user validation. Although this step is not explicitly privileged, it still enables arbitrary code execution in the user's environment and could modify shell startup files or credentials.

Content

Scanner excerpt · references/install-nodejs.md (reported line 20)May include surrounding context.

brew install node@20

方式 2:使用 nvm(Node 版本管理器)

curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash source ~/.bashrc # 或 source ~/.zshrc nvm install 20

text

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This command chains network retrieval directly into privileged shell execution (curl ... | sudo -E bash -), eliminating any opportunity for inspection before code runs as root. In skill documentation, this is especially dangerous because users may copy-paste it verbatim, turning documentation into a delivery mechanism for privilege-compromising code if the source is ever malicious or compromised.

Content

Scanner excerpt · references/install-nodejs.md (reported line 34)May include surrounding context.

Linux (Ubuntu/Debian)

bash
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs

Chaining Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The command -v sudo && sudo npm install -g wjx-cli@latest chain makes privilege escalation part of automated fallback behavior. In the context of installing a remote npm package, this chaining increases the chance that users unintentionally execute privileged network-sourced code, magnifying supply-chain compromise impact to full root execution.

Content

Scanner excerpt · setup.sh (reported line 136)May include surrounding context.

sh
if npm install -g wjx-cli@latest; then
        return 0
    fi
    if command -v sudo &> /dev/null && sudo npm install -g wjx-cli@latest; then
        return 0
    fi
    print_error "wjx-cli 升级失败"

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · setup.sh (reported line 189)May include surrounding context.

sh
echo "请安装 Node.js 20+ 后重新运行本脚本:"
    echo ""
    echo "  macOS:    brew install node"
    echo "  Ubuntu:   curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash - && sudo apt-get install -y nodejs"
    echo "  CentOS:   curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash - && sudo yum install -y nodejs"
    echo "  Windows:  winget install OpenJS.NodeJS"
    echo "  通用:     https://nodejs.org 下载安装"

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · setup.sh (reported line 190)May include surrounding context.

sh
echo "请安装 Node.js 20+ 后重新运行本脚本:"
    echo ""
    echo "  macOS:    brew install node"
    echo "  Ubuntu:   curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash - && sudo apt-get install -y nodejs"
    echo "  CentOS:   curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash - && sudo yum install -y nodejs"
    echo "  Windows:  winget install OpenJS.NodeJS"
    echo "  通用:     https://nodejs.org 下载安装"

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · setup.sh (reported line 189)May include surrounding context.

sh
echo "请安装 Node.js 20+ 后重新运行本脚本:"
    echo ""
    echo "  macOS:    brew install node"
    echo "  Ubuntu:   curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash - && sudo apt-get install -y nodejs"
    echo "  CentOS:   curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash - && sudo yum install -y nodejs"
    echo "  Windows:  winget install OpenJS.NodeJS"
    echo "  通用:     https://nodejs.org 下载安装"

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · setup.sh (reported line 190)May include surrounding context.

sh
echo "请安装 Node.js 20+ 后重新运行本脚本:"
    echo ""
    echo "  macOS:    brew install node"
    echo "  Ubuntu:   curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash - && sudo apt-get install -y nodejs"
    echo "  CentOS:   curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash - && sudo yum install -y nodejs"
    echo "  Windows:  winget install OpenJS.NodeJS"
    echo "  通用:     https://nodejs.org 下载安装"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill clearly directs the agent to execute shell commands such as global npm installs and CLI configuration, but it does not declare any explicit tool scope or allowed-tools boundary. This weakens least-privilege controls and can let the skill run system-modifying actions in environments that rely on manifest-level permissions for safety review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description is very broad and can trigger on common words like survey, form, questionnaire, NPS, or related Chinese terms without requiring clear user intent to use this specific CLI. Overbroad routing increases the chance that the agent invokes installation, configuration, or data-handling workflows in contexts where the user only wanted general advice, creating unnecessary exposure to shell actions and sensitive survey data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill tells the AI to perform a global npm install and run follow-up configuration commands, which are system-modifying actions, but it does not require an upfront safety notice or explicit user approval before changing the host environment. This can lead to unexpected software installation, PATH changes, and persistence on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the AI to accept a user-provided API key and run initialization that likely stores the credential in local config, while only briefly saying not to echo the full key. Without a clear warning about credential persistence, storage location, reuse, and consent, the skill risks mishandling secrets and exposing access to survey/account data if the local machine or logs are compromised.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The package description is written entirely in Chinese and presents the skill as operating in that language, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill implicitly constrains interaction language without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file documents a command that processes encrypted webhook payloads and explicitly includes sensitive inputs like --app_key, --raw_body, signatures, and client IP fields, but it provides no warning about keeping these values confidential or avoiding exposure in shell history/logs. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors affecting privacy or sensitive data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation includes multiple destructive delete operations for departments, tags, admins, contacts, and subaccounts, but only contacts deletion is explicitly marked as irreversible. In an agent skill context, omission of consistent warnings and confirmation guidance can cause the agent or user to execute high-impact administrative changes unintentionally, especially since these commands affect organizational identity and access structures.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The SSO commands generate passwordless login URLs for subaccounts, partner accounts, and legacy user-system users, but the documentation does not warn that these links are sensitive authentication artifacts. In a skill used by an automated agent, this increases the risk of accidental exposure in chat history, logs, screenshots, or redirects, enabling unauthorized access if a generated link is leaked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is written entirely in Chinese and uses mandatory language such as '必须' and '统一用单引号包裹' without indicating that users may choose another language or locale. Under the policy rule, a skill that effectively forces a specific language/locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
97% confidence
Finding

Using sudo -E preserves the caller's environment while executing a remotely piped script as root, increasing the attack surface beyond ordinary privileged execution. Environment inheritance can influence script behavior or interpreter resolution, and combined with curl ... | bash creates a particularly risky installation pattern.

Content

Scanner excerpt · references/install-nodejs.md (reported line 34)May include surrounding context.

Linux (Ubuntu/Debian)

bash
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
97% confidence
Finding

Using sudo -E preserves the caller's environment while executing a remotely piped script as root, increasing the attack surface beyond ordinary privileged execution. Environment inheritance can influence script behavior or interpreter resolution, and combined with curl ... | bash creates a particularly risky installation pattern.

Content

Scanner excerpt · references/install-nodejs.md (reported line 34)May include surrounding context.

Linux (Ubuntu/Debian)

bash
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install-nodejs.md (reported line 35)May include surrounding context.

bash
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L005 states that JSONL 'must use Chinese strings' for key values, which forces a specific language format. This is reinforced by L038 indicating the first-line language defaults to zh, with no opt-in or explanation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all user-facing instructions in a single language and does not provide an opt-in, alternative locale, or justification for restricting usage to Chinese. That creates a natural-language locale policy concern because users are implicitly forced into one language without being given a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script's user-facing title and operational guidance are written in Chinese, and subsequent prompts/help text throughout the file continue that assumption. Because the file provides no user opt-in, alternate locale, or justification for a Chinese-only experience, it conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · setup.sh (reported line 110)May include surrounding context.

sh
local missing=0
    root="$(resolve_install_root)"
    for path in \
        "$root/skills/wjx-cli-use/SKILL.md" \
        "$root/.claude/skills/wjx-cli-use/SKILL.md" \
        "$root/.claude/agents/wjx-cli-expert.md"; do
        if [ ! -s "$path" ]; then

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · setup.sh (reported line 111)May include surrounding context.

sh
local missing=0
    root="$(resolve_install_root)"
    for path in \
        "$root/skills/wjx-cli-use/SKILL.md" \
        "$root/.claude/skills/wjx-cli-use/SKILL.md" \
        "$root/.claude/agents/wjx-cli-expert.md"; do
        if [ ! -s "$path" ]; then

Static analysis

No suspicious patterns detected.