Back to skill

Security audit

wjx-mcp-use

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Wenjuanxing survey administration, but it exposes powerful account, SSO, contact, response-submission, and irreversible deletion capabilities without enough agent-side safeguards.

Install only if you trust the publisher and intend to let an agent administer real Wenjuanxing assets. Before use, require manual confirmation for deletes, response clearing, account/contact changes, SSO links, and imported submissions; avoid using the CLI command-line API-key example with a real key, and prefer scoped credentials stored through a safer secret mechanism.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:45
Finding

Unpinned Global Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 45
Vulnerability Type: Unsafe third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippet

markdown
- **cli_version 未安装**:可选;CLI `0.4.2` 已发布到 npm,先执行 `npm install -g wjx-cli@latest`,成功后再执行 `wjx skill install --force`,然后用 `wjx init --api-key <key>` 统一配置

Technical Analysis

The optional setup instructions install wjx-cli@latest globally. The latest tag is mutable, so the installed package can differ from the version reviewed when this Skill was published. The instruction provides no exact version pin, package-integrity hash, publisher verification, lockfile, or lifecycle-script restriction.

An npm package can run installation lifecycle scripts. A compromised maintainer account, malicious newly published release, or upstream package compromise could therefore result in arbitrary code execution under the privileges of the user running npm. Global installation also expands the impact by modifying the user's global Node.js tool environment.

This behavior is not the minimum privilege necessary for a documentation-only Skill. The same functionality could use an audited, exactly pinned version installed locally or in an isolated environment.

Attack Path

  1. An attacker compromises the wjx-cli package, its publisher account, or a relevant dependency.
  2. The attacker publishes a malicious version and assigns or causes it to receive the latest npm tag.
  3. A user follows the Skill instructions and runs npm install -g wjx-cli@latest.
  4. npm downloads the mutable package version and may execute its lifecycle scripts.
  5. Malicious code runs with the user's privileges and can access files, credentials, network resources, and globally installed tooling available to that account.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the invoking user. The resulting scope may include reading or modifying u ...[truncated 242 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace wjx-cli@latest with an audited, exact version such as the explicitly referenced wjx-cli@0.4.2, after verifying that release.
  • Publish and verify the expected package integrity digest and official publisher or repository information.
  • Prefer a project-local or isolated installation over a global installation.
  • Use a lockfile where applicable and review transitive dependencies.
  • Disable npm lifecycle scripts with --ignore-scripts if the package does not require them.
  • If lifecycle scripts are required, document and audit them before recommending installation.
  • Advise users not to run package installation with administrator or root privileges.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:45
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 45
Vulnerability Type: Sensitive credential exposure
Risk Level: Medium

Vulnerable Code Snippet

markdown
- **cli_version 未安装**:可选;CLI `0.4.2` 已发布到 npm,先执行 `npm install -g wjx-cli@latest`,成功后再执行 `wjx skill install --force`,然后用 `wjx init --api-key <key>` 统一配置

Technical Analysis

The documented initialization command passes the Wenjuanxing API key directly as a command-line argument:

shell
wjx init --api-key <key>

Command-line secrets can be exposed through shell history, process listings while the command is running, terminal capture, audit telemetry, command logging, CI/CD logs, and support transcripts. Redaction performed by the later get_config operation does not protect the original command invocation.

The API key authenticates network operations that include survey management, response access, contact and sub-account administration, SSO generation, file upload, and destructive actions. Consequently, exposing it creates a meaningful account-compromise risk.

Attack Path

  1. A user substitutes a real API key into the documented command and executes it.
  2. The shell records the complete command in history, or monitoring and automation infrastructure captures the process arguments.
  3. Another local user, administrator, log reader, support operator, or attacker with access to the retained logs retrieves the key.
  4. The attacker configures a client with the stolen credential.
  5. The attacker invokes Wenjuanxing API functionality allowed by the key, subject to the affected account's server-side permissions.

Impact Assessment

A stolen key may allow unauthorized access to surveys and potentially sensitive response records, including answer content, submission metadata, source information, and IP addresses. Depending on account permissions, it may also permit survey modification or deletion, response deletion, file upload, contact or sub-account administration, ...[truncated 228 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not accept API keys directly through visible command-line arguments.
  • Make the CLI read the key from an interactive hidden prompt, standard input, or a protected secret store.
  • If environment-based initialization is necessary, read WJX_API_KEY internally without echoing its value or reproducing it in logs.
  • Document how to remove any historical command containing a real key from shell history and advise rotation after suspected exposure.
  • Ensure configuration files containing credentials are created with restrictive permissions.
  • Apply centralized redaction to process, terminal, CI/CD, and diagnostic logs.
  • Support scoped and revocable credentials where the service permits them, and grant only the permissions required for the intended workflow.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises activation on a very broad set of generic terms such as “表单”, “survey”, and “questionnaire”, which can cause it to trigger in benign conversations that only loosely mention those concepts. Over-broad activation increases the chance of inappropriate tool routing, unintended access to survey-management capabilities, and prompt-context injection from this skill into unrelated tasks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and all instructional content are presented exclusively in Chinese, and the examples, labels, and required syntax markers are Chinese-specific. Because the document does not state that the skill is region-specific or offer an opt-in language choice, it constitutes a natural-language locale policy concern under the stated rule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation exposes irreversible deletion capabilities for contacts and administrators but does not instruct the agent to require explicit user confirmation, restate the targets, or warn about irreversibility before invoking them. In an MCP/agent setting, missing guardrails around destructive actions increases the risk of accidental or prompt-induced data loss against real organizational directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section documents tools handling passwords, phone numbers, email addresses, participant identifiers, and SSO login URL generation, but does not include privacy or credential-handling restrictions. In agent use, that omission can lead to unsafe collection, logging, display, or transmission of secrets and personally identifiable information, and SSO links may grant direct account access if exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The real-time query mode removes successfully queried responses from a queue, making the read operation state-changing and non-repeatable. Without a prominent warning and guidance on when this is appropriate, an agent may unintentionally consume queued responses, causing data loss from downstream workflows or breaking auditability/reprocessing expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documented submit_response flow enables proxy submission, importing, or fabrication of survey answers, which can alter business records, pollute analytics, and facilitate fraud or exam abuse. The skill presents detailed mechanics for constructing valid forged submissions but does not clearly constrain usage to authorized testing/import scenarios or disclose this elevated write capability in the high-level manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents a destructive clear_responses capability that permanently deletes survey response data and can optionally reset sequence numbers. While survey management is within the general product domain, this operation is materially more dangerous than ordinary querying/analysis and is not framed with strong authorization, confirmation, or least-privilege safeguards, creating risk of accidental or unauthorized data destruction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Although the markdown notes that clearing responses is irreversible, it does not provide a strong operational warning about authorization, backup/recovery implications, or accidental invocation by an agent. In an agent skill context, terse documentation for a destructive action increases the chance that an LLM or user triggers permanent deletion without appreciating the consequence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation exposes a destructive deletion capability and labels it as '不可恢复', but it does not instruct the agent to require explicit user confirmation, verify ownership, or apply extra safeguards before invoking it. In an agent skill, this omission is dangerous because an LLM may translate a vague or indirect user request into irreversible deletion without a clear second-step confirmation, causing permanent data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The recycle-bin clearing operation is a bulk destructive action, yet the documentation lacks an explicit warning to obtain confirmation or validate scope before use. In this skill context, an agent could interpret broad cleanup language as authorization to purge recoverable surveys, turning a reversible state into permanent loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file contains user-facing operational guidance exclusively in Chinese, and there is no indication that users may request another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.