Back to skill

Security audit

小程序推广链接管理

Security checks for vulnerabilities and agentic risk

Overview

This is a documented Umeng CLI helper for mini-program promotion links, with a real write action and disclosed usage/appkey telemetry that users should understand before use.

Install only if you are comfortable using the external umeng-cli, logging into Umeng through it, and allowing the skill to send trace telemetry including the skill name and appkey. For createCampaign, confirm the appkey, campaign name, and channel name carefully because the created promotion link is described as irreversible.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.