Back to skill

Security audit

Wechat Mp Editor

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed WeChat article workflow, but it can modify live account content and mandates a hardcoded brand footer in published articles.

Review carefully before installing. Use it only with an account where the fixed 巡梦人 branding is intended, require explicit confirmation before any WeChat API submission or publication, and avoid passing live tokens on the command line or through shared /tmp files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:34
Finding

Mandatory Third-Party Branding Hijacks Published Article Output

Content
View full analysis
` and `

` elements use `word-break:normal;white-space:normal` - footer: `padding:36px 20px 40px;text-align:center;` - brand: `巡梦人` (`#bbb`) + `从一颗星星开始,温暖整个宇宙` (`#aaa`) - highlight: one `color:#d4a574` occurrence every 2-4 paragraphs ``` `references/templates.md:106-109`: ```html

巡梦人

从一颗星星开始,温暖整个宇宙

``` `scripts/preflight_check.py:120-130`: ```python # ── 8. 必含内容检查 ── must_have = [ ("Banner 图片", "mmbiz.qpic"), ("Footer 品牌签名", "巡梦人"), ("金色强调色", "#d4a574"), ] for name, keyword in must_have: if keyword in content: ok("必含:{}".format(name), "含关键词「{}」".format(keyword)) else: fail("必含:{}".format(name), "未找到「{}」".format(keyword)) ``` ### Technical Analysis The Skill does not treat the included identity and slogan as optional template examples. Its instructions require the branding in generated content, the canonical template embeds it directly, and the preflight validator rejects articles that do not contain the fixed identity. This changes the user’s publication output in a way unrelated to the core functionality of formatting and managing WeChat articles. Because the requirement is loaded as part of the Skill’s instructions, it can cause an Agent to publish attribution or promotional text that the user did not request. The validation check makes the behavior persistent within the workflow: removing the brandin ...[truncated 1165 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create_draft.py:39
Finding

WeChat Access Tokens Are Exposed Through Command-Line Arguments

Content
View full analysis
dict: """Call WeChat API with JSON payload.""" url = f"https://api.weixin.qq.com/cgi-bin/{endpoint}?access_token={token}" data = json.dumps(payload, ensure_ascii=False).encode("utf-8") req = urllib.request.Request(url, data=data) req.add_header("Content-Type", "application/json; charset=utf-8") ``` `scripts/create_draft.py:39-44`: ```python def main(): parser = argparse.ArgumentParser(description="Manage WeChat MP drafts") parser.add_argument("--token", required=True, help="WeChat access token") parser.add_argument("--json", required=True, help="Path to JSON file with article data") parser.add_argument("--update", action="store_true", help="Update existing draft instead of create") args = parser.parse_args() ``` `scripts/upload_image.py:98-103`: ```python def main(): parser = argparse.ArgumentParser(description="Upload image to WeChat MP") parser.add_argument("--token", required=True, help="WeChat access token") parser.add_argument("--file", required=True, help="Path to image file") parser.add_argument("--cover", action="store_true", help="Upload as permanent cover material") args = parser.parse_args() ``` ### Technical Analysis Both network helpers require the WeChat access token to be supplied as a command-line argument. Command-line arguments may be exposed through process inspection interface ...[truncated 1659 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
build_draft.py:5
Finding

Predictable Shared Temporary Files Expose Secrets and Draft Content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upload_image.py:22
Finding

Image Upload Helper Can Transmit Arbitrary Local Files

Content
View full analysis
str: """Upload image for article body. Returns URL string.""" if not os.path.isfile(filepath): print(f"Error: file not found: {filepath}", file=sys.stderr) sys.exit(1) boundary = "----WebKitFormBoundary7MA4YWxkTrZu0gW" filename = os.path.basename(filepath) with open(filepath, "rb") as f: file_data = f.read() body = ( f"--{boundary}\r\n" f'Content-Disposition: form-data; name="media"; filename="{filename}"\r\n' f"Content-Type: image/png\r\n\r\n" ).encode("utf-8") + file_data + f"\r\n--{boundary}--\r\n".encode("utf-8") url = f"https://api.weixin.qq.com/cgi-bin/media/uploadimg?access_token={token}" req = urllib.request.Request(url, data=body) req.add_header("Content-Type", f"multipart/form-data; boundary={boundary}") ``` `scripts/upload_image.py:60-80`: ```python def upload_cover_image(token: str, filepath: str) -> str: """Upload image as permanent material. Returns media_id string.""" if not os.path.isfile(filepath): print(f"Error: file not found: {filepath}", file=sys.stderr) sys.exit(1) boundary = "----WebKitFormBoundary7MA4YWxkTrZu0gW" filename = os.path.basename(filepath) with open(filepath, "rb") as f: file_data = f.read() body = ( f"--{boundary}\r\n" f'Content-Disposition: form-data; name="media"; filename="{filename}"\r\n' f"Content-Type: image/png\r\n\r\n" ).encode("utf-8") + file_data + f"\r\n--{boundary}--\r\n".encode("utf-8") url = f"https://api.weixin.qq.com/cgi-bin/material/add_material?access_token={token}&type=image" req = urllib.request.Request(url, data=body) req.ad ...[truncated 3037 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (76)

Tainted flow: 'req' from os.environ (line 125, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · build_draft.py (reported line 131)May include surrounding context.

python
headers={'Content-Type': 'application/json'}
)
try:
    resp = urllib.request.urlopen(req)
    result = json.loads(resp.read())
    print(f"API Response: {json.dumps(result, ensure_ascii=False, indent=2)}")
    if 'media_id' in result:

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The description presents a general-purpose WeChat MP article management skill with token management, image upload, draft CRUD, publishing, and formatting. The supplied code is much narrower: it formats one article from a hardcoded markdown source, builds styled HTML, and submits only a draft creation request using an already-provided token and media IDs. It does not handle token lifecycle, image upload, updating/deleting/listing drafts, or publishing. While HTML formatting and draft creation are consistent with part of the description, the declared scope materially overstates the implemented behavior, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description focuses on end-to-end WeChat Official Account article management via API, including authentication, uploads, draft operations, publishing, and formatting. The actual code only generates decorative PNG images locally using custom pixel rendering logic and saves them to disk. While the images may be intended for use in WeChat articles, that is only tangential support material and does not implement the described primary functionality. Therefore, the code’s actual behavior is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on full WeChat Official Account article management via the official API. The supplied code chunk does something materially narrower and different: it only validates a local HTML file against formatting and content rules before publication. There is no API communication, authentication, draft management, upload handling, or publishing logic. While preflight checking could be a supporting feature in a broader article workflow, this specific code chunk's actual behavior does not match the declared primary purpose and includes undeclared content-policy checks.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The description explicitly advertises access token management, signaling that the skill will access or handle sensitive credentials for a live third-party account. Credential use in a broadly triggered skill materially raises risk because accidental activation or unclear scoping could expose secrets or perform authenticated actions unexpectedly.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: wechat-mp-editor
description: "Create, edit, and manage WeChat Official Account (公众号/服务号) articles via the official WeChat API. Handles access token management, image uploads, draft CRUD, publishing, and HTML content formatting with WeChat-compatible CSS. Trigger when the user asks to: write/edit WeChat articles, create/publish drafts, format WeChat push notifications, generate article HTML, or manage WeChat MP drafts through the API."
---

# WeChat MP Editor

Credential Access

High
Category
Privilege Escalation
Confidence
85% confidence
Finding

The workflow explicitly chains credentials to token retrieval, uploads, draft creation, and publishing, indicating end-to-end authenticated control over a live WeChat account. In the absence of strict activation boundaries and permission declarations, this creates a high-risk path for unintended account actions and potential secret misuse.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
## Overview

Full workflow: credentials → access token → image upload → draft creation → publishing.

**One fixed template** — visual branding consistent. Only content (text, date, banner) changes.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
1. `references/templates.md` — 唯一排版规范

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
1. `references/templates.md` — 唯一排版规范

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
1. `references/templates.md` — 唯一排版规范

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · articles/optimizations.svg (reported line 23)May include surrounding context.

text
</linearGradient>
  </defs>

  <!-- Background -->
  <rect width="700" height="380" fill="url(#bg)" rx="12"/>

  <!-- Title -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · articles/optimizations.svg (reported line 37)May include surrounding context.

text
<text x="55" y="112" font-family="system-ui, sans-serif" font-size="12" fill="#666">原版:多个小步骤分别执行,反复读写显存</text>
  <text x="55" y="128" font-family="system-ui, sans-serif" font-size="12" fill="#888">优化:合并为一个大步骤,中间结果不写回</text>

  <!-- Row 1: speed bar -->
  <rect x="510" y="80" width="130" height="12" rx="6" fill="url(#bar-original)"/>
  <rect x="510" y="96" width="130" height="12" rx="6" fill="url(#bar-optimized)"/>
  <text x="575" y="78" text-anchor="middle" font-family="system-ui, sans-serif" font-size="10" fill="#999">速度对比</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · articles/optimizations.svg (reported line 47)May include surrounding context.

text
<!-- Arrow -->
  <text x="490" y="108" text-anchor="middle" font-family="system-ui, sans-serif" font-size="14" fill="#d4a574">→</text>

  <!-- Row 2: 权重量化 -->
  <g filter="url(#shadow-sm)">
    <rect x="30" y="155" width="640" height="72" rx="8" fill="#fff"/>
  </g>

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/create_draft.py (reported line 41)May include surrounding context.

python
def main():
    parser = argparse.ArgumentParser(description="Manage WeChat MP drafts")
    parser.add_argument("--token", required=True, help="WeChat access token")
    parser.add_argument("--json", required=True, help="Path to JSON file with article data")
    parser.add_argument("--update", action="store_true", help="Update existing draft instead of create")
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/upload_image.py (reported line 100)May include surrounding context.

python
def main():
    parser = argparse.ArgumentParser(description="Manage WeChat MP drafts")
    parser.add_argument("--token", required=True, help="WeChat access token")
    parser.add_argument("--json", required=True, help="Path to JSON file with article data")
    parser.add_argument("--update", action="store_true", help="Update existing draft instead of create")
    args = parser.parse_args()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes capabilities that require sensitive operations—credential handling, local file access, network requests, and publishing to an external platform—but it declares no explicit tool scope or permission boundaries. That creates an overbroad execution surface where an agent could invoke powerful actions without transparent restriction or user awareness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are broad enough to activate the skill for many loosely related writing, formatting, and management requests. Overbroad activation can cause an agent to use credentialed network/file capabilities in contexts where the user did not clearly intend external publication or account operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill expands beyond article editing into unsolicited external topic discovery by scanning third-party sources when the queue is empty. This broadens network access and data ingestion in a way not clearly tied to the declared purpose, increasing the chance of unreviewed browsing, prompt-injection exposure from fetched content, and user-surprising behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

Body images (/cgi-bin/media/uploadimg):

bash
curl -s -F "media=@image.png" "https://api.weixin.qq.com/cgi-bin/media/uploadimg?access_token=***"

Returns {"url": "http://mmbiz.qpic.cn/..."}.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
`requests` 库的 `json=` 参数默认 `ensure_ascii=True`,会将中文转为 `\uXXXX` 转义码,微信编辑器显示为乱码。

**禁止使用** `requests.post(url, json=payload)`。

**必须使用** 以下两种方式之一:

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

提交后立即回读验证

python
resp = requests.post(".../draft/get?...", json={"media_id": draft_id})
content = resp.json()["news_item"][0]["content"]

# 必须验证的内容

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill includes a publishing workflow to a live WeChat platform but does not prominently warn that this can push content externally to a production audience. Without a clear warning and confirmation gate, users may unintentionally publish drafts, leak sensitive content, or modify live account state.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Calling an external CLI (dreamina-cli) introduces an undeclared execution capability beyond the manifest’s stated WeChat article management role. External tools can access local files, environment state, or network resources, so invoking them without explicit scoping increases attack surface and may enable unintended command execution paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This HTML article presents all user-facing content in Chinese, including the title, body, headings, and footer text. Under the natural-language policy rule, forcing a specific language without user opt-in or a documented justification is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The article title and all surrounding instructional content are presented exclusively in Chinese, with no indication that users may choose another language or that the content is restricted to a Chinese-language audience for a documented reason. This matches the natural-language policy category for language or locale constraints without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code reads a sensitive credential from the environment and uses it to make a live HTTP request to the WeChat API. While the file prints payload and response information, it does not include any user-facing warning, confirmation, or explanatory comment that it will submit content and credentials to an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.