Back to skill

Security audit

公众号账号诊断

Security checks for vulnerabilities and agentic risk

Overview

The skill performs its advertised WeChat account analysis, but it also has overbroad credential handling, persistent subscription behavior, mandatory promotional output, and unsafe HTML report rendering that users should review before installing.

Install only if you are comfortable giving the skill a Redfox API key, sending queried public-account names or IDs to redfox.hk, and storing generated raw/report data locally. Prefer setting the API key only in the current process or a dedicated secret store, do not let an agent append it to shell startup files or print it, avoid subscription/calendar follow-up unless explicitly desired, and treat generated HTML reports as untrusted until output escaping is fixed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
references/core_workflow.md:313
Finding

Mandatory Third-Party Promotion and Subscription Solicitation in Agent Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/report.py:53
Finding

Stored HTML Injection Through Unescaped Report Data

Content
View full analysis
View' if url else "-" works_rows.append( f"{title}{date_str}{likes}{link}" f"" ) ``` Additional affected construction patterns include: ```python name_html = ( f'' f'{name}' if account_url else name ) similar_cards.append( f'
' f'
{name_html} | ' f'Average reads: {avg_read} | Total interactions: {total_interactive}
' f'
' f'Recommendation:{recommend_reason}
' f'
' f'Posting characteristics:{post_feature}
' f'
' f'Learning point:{learn_point}
' f'
' ) for key, val in replacements.items(): html = html.replace(key, val) ``` The multi-account renderer has the same flaw: ```python for acc in accounts: name = acc.get("header", {}).get("Account name", "") header_cells.append(f"{name}
Remediation
View remediation
``` 8. Add tests using payloads in account names, titles, URLs, descriptions, avatars, recommendations, and comparison fields. 9. Treat local JSON report files as untrusted input, even when they are normally generated by this project. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/api_client.py:21
Finding

Excessive Access to User Shell Configuration Files During Credential Discovery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:68
Finding

Plaintext API-Key Persistence and Full-Secret Terminal Verification

Content
View full analysis
` to `~/.zshrc` or `~/.bashrc`, then source the corresponding file. Windows: Use `[Environment]::SetEnvironmentVariable( "REDFOX_API_KEY", "", "User" )` to set a permanent user-level environment variable. After configuration, verify it with: `echo $REDFOX_API_KEY` or `echo %REDFOX_API_KEY%` ``` ### Technical Analysis The instructions direct the Agent to persist an authentication secret in plaintext user configuration. On Unix-like systems, the key is written to a general shell startup file that may be: - Read by unrelated programs or troubleshooting tools - Included in dotfile repositories or backups - Shared in support bundles - Accidentally committed to source control The verification step prints the complete key to the terminal. Terminal content can be exposed through shell transcripts, screen sharing, command logs, CI output, support captures, or conversation records if an Agent relays the result. The project does not need to display the key to verify that it exists. ### Attack Path 1. The user provides a Redfox API key to the Agent. 2. The Agent follows the Skill instructions and writes the key in plaintext to a shell startup file or a permanent user environment variable. 3. The Agent runs an `echo` command that prints the complete secret. 4. The value is captured through terminal history facilities, logging, screen recording, backups, dotfile synchronization, or an observer. 5. An attacker uses the exposed key to authenticate to Redfox as the affected user. ### Impact Assessment An exposed key may permit unauthorized API requests under the user' ...[truncated 427 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:52
Finding

Unpinned Runtime Dependency Installation

Content
View full analysis
Remediation
View remediation
--hash=sha256: ``` 2. Include all transitive dependencies with hashes. 3. Install with hash enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Recommend installation inside a dedicated virtual environment. 5. Explicitly use a trusted HTTPS package index. 6. Regularly scan and update the lock file for security advisories. 7. Test dependency updates before publishing a new Skill version. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose focuses on account diagnosis, but the skill also reads credentials from local shell startup files, performs external requests to a third-party service, and handles raw account lookup/data retrieval. This mismatch undermines informed consent and can expose local secrets or send data off-device in ways the user did not reasonably expect from the description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The sync command invokes a remote endpoint to trigger data collection/subscription for account works, which goes beyond passive analysis of provided data. This can cause unauthorized external actions, collection of additional data, and user surprise if the tool is expected to only analyze existing account information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly tells users to invoke the skill via unconstrained natural-language requests rather than a narrowly defined command surface. In agent environments, broad activation phrasing can cause accidental routing or unintended invocation from loosely related user text, increasing the chance that the skill runs when the user did not clearly intend it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example phrases such as diagnosing or comparing accounts are short, generic, and overlap with ordinary conversational requests. Because they are not strongly scoped to this specific skill, an orchestrator or agent may mistakenly trigger the skill during unrelated discussions about account analysis, leading to unintended data access or actions within the skill's capability set.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README says users can 'directly use natural language to describe needs, no need to remember commands,' but it does not define clear activation boundaries, exclusions, or a constrained trigger set. This can cause unintended invocation because many ordinary requests could plausibly match the skill's purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises capabilities that require environment access, file reads/writes, and outbound network access, but it does not declare any explicit tool scope or permission boundaries. This can cause the agent to exercise broader capabilities than users expect, increasing the risk of unintended credential access, filesystem modification, and external data transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation promotes data-driven diagnosis via a third-party API but does not clearly warn users that account-related queries and associated data will be sent to an external service. Lack of transparency around third-party data transfer reduces user awareness and may create privacy, compliance, or trust issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to help persist API keys into shell configuration files, which creates long-lived secrets on disk and encourages the agent to modify sensitive startup files. This expands the blast radius of compromise, risks credential leakage through local file access, and may alter user environments in unexpected ways.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad enough that normal conversation about account analysis may unintentionally activate the skill. Accidental activation is risky here because the skill can access credentials and initiate external API-driven analysis workflows without a clearly deliberate invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The HTML document declares lang="zh-CN", which hard-codes a Chinese locale for the generated report. Under the policy, forcing a specific language or locale without user opt-in or a clearly documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow requires users to provide a public-account name in Chinese and the rest of the file hard-codes Chinese-language greetings, templates, and output requirements. This imposes a language/locale constraint without opt-in or an explicit documented justification for limiting the skill to Chinese.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a tool that quantitatively scores a public account across four dimensions and outputs optimization suggestions. However, the workflow opening states it can analyze both operational data and '商业价值', and later the report mandates a subscription/tracking upsell flow for ongoing monitoring, which goes beyond one-off diagnostic scoring and advice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow sends user-supplied account identifiers and related query context to a third-party service without any user-facing disclosure or consent notice. Even if the queried data is public-account metadata, undisclosed transfer to an external provider introduces privacy, compliance, and trust risks, especially where user research targets or usage patterns may themselves be sensitive.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow advertises a subscription/tracking capability that is not disclosed in the manifest, creating a hidden persistence or follow-up data-processing feature beyond the user's expected one-time diagnostic action. Undisclosed ongoing monitoring changes the privacy and consent profile of the skill and can lead to unexpected collection, retention, or repeated transmission of account-related query data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file prescribes a fixed '标准开场白' entirely in Chinese and presents it as required first-turn output. Because the guidance does not offer the user any language choice or state that the skill is limited to Chinese-speaking users for a documented regional reason, it creates a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

When an account is not found, the workflow instructs the agent to actively synchronize or collect data by calling an external interface with a user-supplied identifier. That exceeds a passive diagnostic scope and is risky because unverified user input is transmitted to a third party, potentially causing unintended data processing, privacy issues, or abuse of the sync endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The sync workflow sends account identifiers to an external API endpoint but provides no clear privacy or data-transmission warning. This is risky because even if the identifier is business-related rather than personal, transmitting user-supplied identifiers to a third party without transparent notice and consent can violate user expectations and organizational data-handling policies.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow expands a passive account-analysis skill into persistent task scheduling and automatic future push behavior via calendar creation. This is dangerous because it creates stateful side effects and delayed actions outside the user’s immediate analysis request, which can surprise users, retain account identifiers longer than expected, and trigger follow-up actions without sufficiently explicit consent boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The subscription flow creates a calendar task and promises an automatic future push, but it does not clearly warn the user that account identifiers and task metadata will be stored for later execution. This is dangerous because users may consent to analysis without understanding the retention, automation, and follow-up processing involved, undermining informed consent and privacy expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document contains conflicting instructions for missing-account handling: one section says to ask the user to re-enter correct information, while the workflow elsewhere initiates sync and subscription actions. Such contradictions are dangerous because they make agent behavior unpredictable, increasing the chance of unauthorized external calls or task creation in scenarios where the safer behavior should be to stop and ask for corrected input.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code persists full raw API responses and generated analysis reports to local JSON files in an output directory. If the queried account data includes identifiers, profile metadata, works, or similar-account information, this creates unnecessary at-rest retention and expands exposure beyond transient analytics behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code writes raw account data and analysis output to local files without any visible notice, consent flow, or retention disclosure in this file. Even if the data is not highly sensitive, silent persistence increases privacy and compliance risk because users may reasonably expect analysis to be in-memory only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The query workflow sends account names and identifiers to remote APIs without any disclosure or visible consent mechanism in this code path. In an analytics tool this may be expected operationally, but undisclosed transmission still creates privacy and trust issues and may violate platform or organizational expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code enumerates and reads user shell startup files (.zshrc, .bashrc, .bash_profile, .profile) to extract an API key when the environment variable is absent. This expands the skill’s access to sensitive local configuration beyond what is necessary for a公众号 analysis tool, and can unintentionally expose unrelated secrets stored in those files or normalize secret harvesting behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The fallback credential lookup reads sensitive shell configuration files without any user-facing notice, consent, or disclosure. Even if intended as convenience, silently accessing these files violates least surprise and can expose credentials or private configuration data from locations unrelated to the skill’s stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.