Back to skill

Security audit

微信公众号自动发布增强版

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its WeChat draft-publishing purpose, but it needs review because it handles WeChat account secrets and uploads article files with weak credential-safety guidance.

Install only if you are comfortable letting the skill create WeChat drafts and upload the selected article text, title, and cover image to WeChat. Do not paste APPSECRET into prompts or pass it on the command line; use protected environment injection or a secret manager, and rotate the secret if it has already appeared in shell history or logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
wechat_publish.py:25
Finding

Sensitive WeChat credentials and access tokens exposed through URLs and command-line arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (13)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1)May include surrounding context.

md
# 寰俊鍏紬鍙疯嚜鍔ㄥ彂甯冩妧鑳?
馃摑 **涓€閿彂甯?Markdown/HTML 鏂囩珷鍒板井淇″叕浼楀彿鑽夌绠?*

---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

bash
cd C:\Users\JMO\.openclaw\workspace\skills\wechat-publisher-pro
copy .env.example .env

缂栬緫 .env 鏂囦欢锛屽~鍏ヤ綘鐨勯厤缃細

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire policy is written exclusively in Chinese and does not offer any language or locale choice, despite describing a broad scope covering all public articles, technical documents, and tutorials. Under the stated policy criteria, a skill should not force a specific language unless it is opt-in or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The title and the entire checklist are written specifically for a WeChat public-account publishing workflow, which effectively constrains the skill to Chinese-language output. The file does not state that language choice is optional or explain a justified regional/language policy exception, so it may violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README instructs users to place WECHAT_APPID and WECHAT_APPSECRET into a local .env file but does not warn against committing that file to source control, sharing it in prompts, or exposing it in logs. In an agent skill context, omission of secret-handling guidance increases the chance that users paste credentials into chat or store them insecurely, leading to credential leakage and unauthorized use of the WeChat account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes publishing article content and cover images to the external WeChat platform but does not clearly disclose that local files and text will be transmitted off-system to a third-party service. Users may unknowingly send sensitive or unpublished content through the skill, causing confidentiality and privacy risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly automates publishing articles and cover images to a third-party platform, but the description does not warn users that their article content and media will be transmitted to WeChat servers. This omission can cause users to unknowingly upload sensitive, proprietary, or regulated content, especially because the feature is presented as a convenient one-click action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s user-facing description is entirely in Chinese and explicitly targets WeChat official account publishing, but it does not offer any language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · wechat_publish.py (reported line 25)May include surrounding context.

python
def get_token(self):
        """获取 access_token"""
        url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={self.appid}&secret={self.appsecret}"
        resp = requests.get(url, timeout=10)
        result = resp.json()
        if "access_token" in result:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · wechat_publish.py (reported line 38)May include surrounding context.

python
def get_token(self):
        """获取 access_token"""
        url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={self.appid}&secret={self.appsecret}"
        resp = requests.get(url, timeout=10)
        result = resp.json()
        if "access_token" in result:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · wechat_publish.py (reported line 78)May include surrounding context.

python
def get_token(self):
        """获取 access_token"""
        url = f"https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={self.appid}&secret={self.appsecret}"
        resp = requests.get(url, timeout=10)
        result = resp.json()
        if "access_token" in result:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The file content and example invocation language are entirely Chinese, and no opt-in or justification for a Chinese-only workflow is provided. Under the language/locale policy, forcing a specific language without user choice can be a natural-language policy issue unless the regional constraint is clearly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing instructions and examples are presented only in Chinese, with no indication that other languages are supported or that the Chinese-only presentation is intentional for a region-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy concern unless the locale limitation is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.