Back to skill

Security audit

Weixin Long Image

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but its HTML-to-image renderer can run active HTML with unrestricted browser networking, so users should review it before installing.

Install only if you expect this skill to render Weixin content into images and you trust the HTML it will render. Avoid feeding it untrusted HTML, remote images, scripts, iframes, or sensitive content unless the renderer is isolated or updated to block network requests and JavaScript. Keep outputs under /tmp or the workspace and delete only files created for the current render.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_long_image.py:25
Finding

Untrusted HTML Executes with Unrestricted Browser Networking

Content
View full analysis
None: with sync_playwright() as p: browser = p.chromium.launch() page = browser.new_page( viewport={"width": width, "height": 1000}, device_scale_factor=scale, ) page.goto(html_path.resolve().as_uri(), wait_until="networkidle") page.screenshot(path=str(png_path), full_page=True) browser.close() ``` The renderer accepts HTML from a file, an inline command-line value, or standard input: ```python def read_input(value: str | None) -> tuple[str, Path | None]: if value is None: return sys.stdin.read(), None candidate = Path(value) if candidate.exists() and candidate.is_file(): return candidate.read_text(encoding="utf-8"), candidate return value, None ``` ### Technical Analysis The supplied HTML is opened in a JavaScript-capable Chromium instance. The renderer does not disable JavaScript, intercept network requests, enforce a URL allowlist, inject a restrictive Content Security Policy, or isolate the browser from loopback and private network addresses. Consequently, attacker-controlled HTML can contain active elements such as: ```html ``` It can also initiate requests through images, stylesheets, frames, or scripts without requiring JavaScript: ```html ``` Browser same-origin controls may prevent reading many cross-origin responses, but they do not prevent sending requests. Depending on ...[truncated 1630 chars]
Remediation
View remediation
``` 5. Separate trusted and untrusted rendering modes. Any mode that enables JavaScript or remote resources should require an explicit opt-in and should execute inside a network-isolated, disposable sandbox. 6. Do not place secrets or sensitive environment information in the rendered DOM unless active content and outbound communication have been reliably disabled. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/render_long_image.py:57
Finding

Unbounded Rendering Parameters and Page Dimensions Permit Resource Exhaustion

Content
View full analysis
Remediation
View remediation
({ width: document.documentElement.scrollWidth, height: document.documentElement.scrollHeight }) """) ``` Reject documents whose width, height, or estimated physical pixel count exceeds configured limits. The estimate should account for device scale factor. 4. Set explicit navigation, rendering, and screenshot timeouts. Abort the browser context when the overall rendering deadline is exceeded. 5. Block unnecessary network access and cap the number and size of loaded resources. 6. Run Chromium in an isolated worker with operating-system or container limits for memory, CPU, execution time, process count, and writable disk space. 7. Write output through a quota-controlled temporary area and reject screenshots expected to exceed the permitted output size. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (8)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The skill includes a destructive cleanup command pattern using rm -f on paths that are described abstractly rather than being programmatically constrained. If the output path is influenced by user-controlled input, variable expansion, or agent error, the cleanup step could delete arbitrary local files, making this significantly more dangerous than ordinary temp-file handling.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

Typical cleanup:

bash
rm -f /absolute/path/to/output.png /absolute/path/to/output.html

Rules:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to read templates and write/delete HTML and PNG files, but it does not declare any explicit tool scope or allowed-tools boundary. That omission weakens least-privilege controls and makes it easier for the skill to gain broader filesystem access than is necessary, especially because the workflow includes temporary-file creation and deletion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description uses broad triggers like 'beautiful visual,' 'poster-like output,' and 'content benefits from HTML-based rendering,' which can match many ordinary user requests. Ambiguous activation criteria increase the chance the skill is invoked unexpectedly, causing unintended file operations, rendering, and outbound message behavior without a clear user request for this specific workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The 'When To Use' section contains subjective conditions like 'hard to read,' 'visually polished,' and 'stable final presentation,' which do not provide clear security or operational boundaries. In practice, that can over-trigger the skill and expand the circumstances under which the agent reads templates, generates files, and sends media, increasing the attack surface and risk of unintended actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction mandates use of Asia/Shanghai time to switch to dark-mode defaults after 22:00, imposing a locale-specific behavior regardless of the user's actual location or preference. This is a natural-language policy concern because it hard-codes a regional assumption without offering user choice or justification as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script renders attacker-controlled or user-supplied HTML in a real Chromium instance and waits for network idle, which allows embedded external resources such as images, stylesheets, fonts, iframes, or script-driven requests to be fetched automatically. In the context of an agent skill, this can cause unintended outbound network access, IP/data leakage, tracking beacons, and SSRF-like access to internal or local network resources if untrusted HTML is rendered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The HTML root element sets lang="zh-CN", which forces a specific language/locale in the template. This can violate the language/locale policy when the skill does not offer user opt-in or explain that the template is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file is subject to natural-language policy checks for locale constraints. The root HTML tag hard-codes the document language to Simplified Chinese, and there is no indication in the file that users can choose another language or that the locale restriction is justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.