Back to skill

Security audit

Wechat Md Publisher Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-built for WeChat publishing, but it has enough high-impact publishing and credential-handling risk, plus inconsistent publish-before-review examples, that users should review it carefully before installing.

Install only if you are comfortable giving this tool access to a WeChat public account and local article files. Use a test or least-privileged account first, keep AppSecret out of shell history and process lists, prefer draft creation with manual review, and do not use remote themes unless you trust the third-party endpoint receiving article content. Audit `wechat-md-publisher@1.0.7` before using production credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
config.json:78
Finding

Third-Party Executable Dependencies Are Installed Without Cryptographic Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (26)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
- 本 Skill 的启动器 (`scripts/run.js`) 不会执行任何子进程,也不会通过 `npx` 在运行时从 registry 拉取代码。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 257)May include surrounding context.

md
- 本 Skill 的启动器 (`scripts/run.js`) 不会执行任何子进程,也不会通过 `npx` 在运行时从 registry 拉取代码。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 717)May include surrounding context.

md
- 本 Skill 的启动器 (`scripts/run.js`) 不会执行任何子进程,也不会通过 `npx` 在运行时从 registry 拉取代码。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description immediately presents itself in Chinese and the usage examples throughout the README assume Chinese-language prompts and content. There is no opt-in, alternative locale guidance, or statement that the skill is intentionally limited to Chinese-only use for a documented regional/compliance reason.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

This duplicate finding points to the same risky documentation pattern: the sample workflow normalizes immediate publication rather than draft-first behavior. Although the README later warns to prefer drafts and confirmation, the earlier command example can still train an agent or user toward a state-changing action without enough safeguards.

Content

Scanner excerpt · README.md (reported line 105)May include surrounding context.

EOF

发布

wechat-pub publish create --file test.md --theme default

text

## 🎯 使用方式

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

This duplicate finding points to the same risky documentation pattern: the sample workflow normalizes immediate publication rather than draft-first behavior. Although the README later warns to prefer drafts and confirmation, the earlier command example can still train an agent or user toward a state-changing action without enough safeguards.

Content

Scanner excerpt · README.md (reported line 105)May include surrounding context.

EOF

发布

wechat-pub publish create --file test.md --theme default

text

## 🎯 使用方式

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger keyword list contains broad phrases without constraints or disambiguation rules, making accidental invocation more likely. In this skill, mistaken activation is more serious because it can use stored credentials, access local files, and modify drafts or published content on a production WeChat account.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 566)May include surrounding context.

bash
# 批量创建草稿
for file in articles/*.md; do
    wechat-pub draft create --file "$file" --theme default
done

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 566)May include surrounding context.

bash
# 批量创建草稿
for file in articles/*.md; do
    wechat-pub draft create --file "$file" --theme default
done

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example dialogue shows the AI immediately publishing content after a generic user request, which directly contradicts the earlier draft-first and explicit-confirmation safety policy. In an agent setting, examples strongly shape behavior, so this inconsistency can cause accidental public posting of unreviewed or noncompliant content to a live WeChat account.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example uses broad natural-language phrasing that can normalize triggering a high-impact publishing skill from an imprecise request. For a user-invocable skill that can change external state and publish to a live audience, ambiguous invocation cues raise the risk of accidental activation and unintended content release.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The later AI workflow example again depicts direct publication despite the documented requirement to default to draft creation and wait for user approval. Repeated contradictory guidance increases the chance an LLM or operator will follow the unsafe example rather than the policy text, leading to unintended external publication.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Toutiao reposting example presents a generic transfer request followed by a successful immediate publish flow, conflicting with the explicit confirmation requirement for AI automation. Because reposting third-party news carries legal, brand, and compliance risks, bypassing review is especially dangerous in this context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · config.json (reported line 134)May include surrounding context.

json
"保护 ~/.config/wechat-md-publisher-nodejs/ 目录权限(建议 0700),并将其排除在备份/同步/容器镜像之外",
      "在条件允许时使用最小权限或测试公众号验证流程后,再切换到生产账号",
      "如怀疑泄露,立即在微信公众平台重置 AppSecret 并删除本地缓存目录",
      "AI / 自动化场景下,默认走 draft create + 人工确认路径,避免在未审阅的情况下直接 publish"
    ]
  },
  "permissions": {

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · config.json (reported line 134)May include surrounding context.

json
"保护 ~/.config/wechat-md-publisher-nodejs/ 目录权限(建议 0700),并将其排除在备份/同步/容器镜像之外",
      "在条件允许时使用最小权限或测试公众号验证流程后,再切换到生产账号",
      "如怀疑泄露,立即在微信公众平台重置 AppSecret 并删除本地缓存目录",
      "AI / 自动化场景下,默认走 draft create + 人工确认路径,避免在未审阅的情况下直接 publish"
    ]
  },
  "permissions": {

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/ip-whitelist-guide.md (reported line 214)May include surrounding context.

wechat-pub account add --name "公众号" --default

4. 使用:建议先创建草稿,人工确认后再 publish

wechat-pub draft create --file article.md --theme default

text

**方案 2:申请固定 IP**

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/ip-whitelist-guide.md (reported line 214)May include surrounding context.

wechat-pub account add --name "公众号" --default

4. 使用:建议先创建草稿,人工确认后再 publish

wechat-pub draft create --file article.md --theme default

text

**方案 2:申请固定 IP**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document is entirely written in Chinese and assumes a WeChat/Chinese-platform workflow, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is natural-language documentation, and all headings, descriptions, and instructions are presented only in Chinese. Under the policy rule, forcing a specific language without user opt-in or a documented regional justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script’s user-facing instructions, warnings, and operational guidance are presented only in Chinese. This imposes a specific language on all users without any documented opt-in, fallback, or locale selection, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/postinstall.js (reported line 57)May include surrounding context.

js
--default

   ${YELLOW}# 2. 发布文章${RESET}
   wechat-pub publish create \\
     --file article.md \\
     --theme orangesun

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/postinstall.js (reported line 57)May include surrounding context.

js
--default

   ${YELLOW}# 2. 发布文章${RESET}
   wechat-pub publish create \\
     --file article.md \\
     --theme orangesun

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code presents the help text and multiple user-facing status/error messages only in Chinese, including the primary usage instructions and runtime output. That creates a language/locale policy issue because the skill does not offer a user opt-in, fallback language, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

文档全文以中文描述技能行为和 AI 回复方式,但没有注明这是面向中文用户的区域性工具,或声明代理应根据用户语言偏好响应。对于组织语言政策而言,这种默认单一语言而无 opt-in 说明存在合规风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

SQP-3 适用于所有文件类型。文档中的自然语言示例和整体交互指引均默认使用中文,且未说明可根据用户语言偏好切换,这可能构成未获用户选择的语言/locale 约束。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.