Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Wechat Publisher Skill

v2.0.3

Automatically collects AI news, formats in HTML block layout v3.0, and publishes 32 news items to WeChat public account draft with scheduling and deduplication.

0· 76·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for 403914291/wechat-publisher-easy.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Wechat Publisher Skill" (403914291/wechat-publisher-easy) from ClawHub.
Skill page: https://clawhub.ai/403914291/wechat-publisher-easy
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install wechat-publisher-easy

ClawHub CLI

Package manager switcher

npx clawhub@latest install wechat-publisher-easy
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The SKILL.md and included scripts clearly require a WeChat AppID and AppSecret and access to the user's WeChat material library, yet the registry metadata lists no required environment variables or credentials. The documentation claims a fixed 'block-v3' template and 32 items, but config/default.json defaults to v5-simple and 15 items; templates referenced in docs and code are inconsistent. The skill also references local cache paths (e.g., D:\news) and writes license/usage files under its memory dir — reading/writing local files is plausible for deduplication, but the mismatch between declared and actual requirements is an incoherence the user should understand.
!
Instruction Scope
Runtime instructions and docs direct the agent to read local caches (memory/, D:\news), load/save config and license files, call external services (ip-api.com to detect public IP) and the WeChat API, and run diagnostics that reveal config contents. Troubleshooting explicitly suggests hard-coding AppID/AppSecret into scripts when environment variables are 'unavailable' — that expands scope to storing secrets in plaintext files and logs. The instructions also guide purchase/activation flows (openclaw skill buy) that involve contacting external parties; none of these extra steps are reflected in the registry metadata.
Install Mechanism
There is no external install script or remote download referenced by the registry — this is an instruction-and-code bundle included in the skill archive. No high-risk external installers or URL downloads are present in the provided files. The code depends on requests (Python) which is a standard library dependency.
!
Credentials
Requesting AppID/AppSecret is proportionate for publishing to a WeChat public account. However, the registry did not declare these credentials, and the docs/code recommend insecure practices (hard-coding secrets into scripts, storing them in config files, diagnostic outputs that reveal partial secrets). The skill reads local caches and a Windows D:\news path (presented as dedup cache) — access to arbitrary local paths should be limited and clearly justified. Overall the secret-handling guidance is unsafe and not properly reflected in metadata.
Persistence & Privilege
The skill does not set always:true and does not attempt to modify other skills or global agent configuration. It writes token/usage/license files into its own memory directory (normal for this type of tool). Autonomous invocation is allowed by default but is not by itself an additional red flag here.
What to consider before installing
Key things to consider before installing: - Don’t trust the registry metadata alone: this skill actually needs your WeChat AppID and AppSecret but the registry lists no required credentials — confirm with the publisher before supplying secrets. - Inspect publish.py fully (and run it in a sandbox) to see every network endpoint it calls. It legitimately calls api.weixin.qq.com for tokens, but the docs also instruct use of ip-api.com and include diagnostic scripts that may reveal secrets; verify there are no hidden remote endpoints or telemetry to unknown hosts. - Never hard-code AppSecret/AppID into scripts or store them in world-readable files. If you must use this skill, prefer storing secrets in a secure vault or environment variables and restrict file permissions on config files. - The docs recommend reading/creating files under D:\news and memory/ — check what local files the skill will read to ensure it won't accidentally exfiltrate unrelated data. - Template/setting inconsistencies (block-v3 vs v5-simple, news_count 32 vs 15) suggest sloppy packaging — ask the maintainer for a canonical source (GitHub repo or official homepage) and a clear security/privacy statement. - If you want to proceed for testing: run the skill in an isolated environment or sandbox, restrict outbound network access to only api.weixin.qq.com and the WeChat media endpoints, and monitor file writes/reads and network connections. If you need, I can: (1) point out specific lines in publish.py to inspect further, (2) produce a minimal checklist to sandbox and test the skill safely, or (3) draft a short message you can send to the maintainer requesting clarification about credentials, telemetry, and template/version mismatches.

Like a lobster shell, security has layers — review code before you run it.

latestvk977s4gcm83kkayjwtj1ky4z39846j6g
76downloads
0stars
1versions
Updated 3w ago
v2.0.3
MIT-0

微信公众号发布技能

技能名称: wechat-publisher
版本: V2.0.0(块布局 v3.0)
描述: 自动发布 AI 新闻到微信公众号草稿箱(块布局固定版)
作者: 小蛋蛋
技术支持: 403914291@qq.com
公众号: 心识孤独的猎手
微信: 心识孤独的猪手


📋 功能特性

  • ✅ 自动收集 32 条 AI 新闻(4 类×8 条)
  • ✅ 自动生成 HTML 格式内容(块布局 v3.0)
  • ✅ 自动发布到公众号草稿箱
  • 固定模板:块布局 v3.0(官方唯一模板)
  • ✅ 50 次免费试用 + 8.8 元永久买断
  • ✅ 支持自定义发布时间(默认 06:00)
  • ✅ 支持 IP 白名单自动检测
  • ✅ 新闻分类:国外 AI + 国际动态 + 国内大厂 + 其他科技
  • 智能去重:30 天历史对比,避免重复新闻
  • 字体优化:整体加大 2 号(基准 13px)
  • 二维码优化:素材库 qrcode.jpg(200×200px)

🎨 块布局 v3.0(固定版)

整体结构

顺序板块内容
1头部 Banner北京天气 + 北京时间 + AI 科技新闻速览
2今日摘要8 条要点,紫色卡片
3目录导航AI 科技新闻速览 (4 类) + 序号标签
4阅读提示蓝色提示框,显示总条数
5国外 AI 新闻8 条,紫色主题
6国际科技动态8 条,粉红主题
7国内大厂8 条,蓝色主题
8其他科技新闻8 条,绿色主题
9底部关注公众号二维码 + 版权信息

字体规范

元素字体大小
整体基准13px
头部标题14px
摘要标题15px
目录标题15px
新闻标题14px
新闻内容13px
底部标题16px

二维码规范

  • 图片名称: qrcode.jpg
  • 位置: 素材库
  • 尺寸: 200×200px
  • 样式: 白色背景框 + 圆角 + 阴影

🔧 配置项

配置项说明默认值是否必填
app_id公众号 AppID-✅ 是
app_secret公众号 AppSecret-✅ 是
schedule发布时间06:00❌ 否
template发布模板block-v3❌ 否
news_count新闻条数32❌ 否
timezone时区Asia/Shanghai❌ 否
qrcode_url二维码 URL素材库 qrcode.jpg❌ 否

📖 使用说明

安装技能

openclaw skill install wechat-publisher

配置技能

openclaw skill config wechat-publisher

设置发布时间

openclaw schedule wechat-publisher 06:00

查看状态

openclaw skill status wechat-publisher

发布测试

openclaw skill run wechat-publisher --test

💰 授权说明

  • 试用版: 50 次免费使用(约 1 个月)
  • 专业版: 8.8 元永久买断
  • 购买命令: openclaw skill buy wechat-publisher

📊 试用次数说明

50 次免费试用包含:

  • ✅ 测试块布局 v3.0 模板
  • ✅ 配置调试和学习成本
  • ✅ 约 1 个月的实际使用
  • ✅ 充分体验自动发布功能

试用次数用完后:

  • 运行 openclaw skill buy wechat-publisher 购买专业版
  • 8.8 元永久买断,无限次使用

⚠️ 重要配置

IP 白名单配置

微信公众号后台需要添加服务器 IP 到白名单:

  1. 登录 https://mp.weixin.qq.com/
  2. 设置 → 公众号设置 → 功能设置
  3. 找到 IP 白名单
  4. 添加当前出口 IP(运行 curl http://ip-api.com/json/ 查看)

如未配置 IP 白名单,API 调用会返回 40164 invalid ip 错误。

二维码图片配置

公众号素材库需要上传二维码图片:

  1. 登录公众号后台 → 素材管理 → 图片
  2. 上传公众号二维码图片
  3. 命名为 qrcode.jpg
  4. 系统自动使用此图片

📞 支付联系方式

支付流程:

  1. 运行购买命令后,系统生成订单
  2. 用户扫码支付(微信/支付宝)
  3. 支付成功后,通过以下方式联系管理员获取激活码:
联系方式说明
微信添加管理员微信:lylovejava(备注:技能购买)
公众号关注"小蛋蛋助手"公众号,发送订单号
邮箱support@wechat-publisher.ai(24 小时内回复)
GitHubhttps://github.com/403914291 提交 Issue

自动激活(推荐):

  • 支付成功后,系统自动发送激活码到用户邮箱
  • 或在购买界面直接显示激活码

📁 文件结构

wechat-publisher-skill/
├── SKILL.md              # 技能定义文件
├── publish.py            # 核心发布脚本
├── scripts/
│   ├── install.sh        # 安装脚本
│   └── activate.py       # 激活脚本
├── templates/
│   ├── block-v3.html     # 块布局 v3.0(固定版)
│   └── ...               # 其他模板(历史版本)
├── config/
│   └── default.json      # 默认配置
└── docs/
    ├── USER_GUIDE.md     # 用户手册
    ├── BLOCK_LAYOUT.md   # 块布局规范
    └── TROUBLESHOOTING.md # 故障排查手册

📖 文档链接


📝 更新历史

版本日期更新内容
V1.02026-03-24初始版本
V1.12026-03-29新增超链接 + 其他科技新闻
V2.02026-04-04固定版:块布局 v3.0 + 二维码修正 + 字体加大

创建日期:2026-03-26
最后更新:2026-04-04 19:09
更新内容:块布局 v3.0 固定版,二维码使用素材库 qrcode.jpg,整体字体加大 2 号

Comments

Loading comments...