Back to skill

Security audit

super-weiyun-skill

Security checks for vulnerabilities and agentic risk

Overview

This Weiyun cloud-storage skill is mostly coherent, but it handles account cookies and local downloads in ways that need careful review before use.

Install only if you trust this skill with your Tencent Weiyun account and private cloud files. Prefer QR login over pasted cookies, avoid passing cookies on the command line, restrict or delete cookies.json after use, avoid recursive downloads from untrusted/shared Weiyun folders, be cautious with --overwrite, and review all delete, permanent delete, recycle-bin clearing, and public share operations before running them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
weiyun_skills/login.py:32
Finding

Authentication Cookies Are Persisted in Plaintext Without Enforced Access Controls

Content
View full analysis
None: """Save cookies data to a JSON file. Args: cookies_data: Cookies data to save. save_path: File path to save cookies. """ cookies_data["update_time"] = get_timestamp() with open(save_path, "w", encoding="utf-8") as f: json.dump(cookies_data, f, ensure_ascii=False, indent=2) ``` The CLI also accepts the complete cookie string as a command-line argument: ```python parser.add_argument( "--cookies", type=str, default="", help="Cookie string from browser (required for cookies method)" ) ``` A similar option exists in `weiyun_skills/main.py`: ```python parser.add_argument( "--cookies", type=str, default=None, help="Cookies string (overrides cookies.json)" ) ``` ### Technical Analysis The `_save_cookies` function writes the complete Tencent authentication state to a plaintext JSON file. The saved data includes both `cookies_str` and `cookies_dict`, which can contain reusable session credentials such as `p_skey`, `skey`, `pt4_token`, and related account cookies. The file is created with the process's default permissions, subject only to the current umask. The implementation does not: - Explicitly restrict the file to owner-only access, such as mode `0600`. - Check whether the destination is a symbolic link. - Use atomic and exclusive file creation. - Encrypt the credential material or use an operating-system credential store. - Warn the user if the destination is accessible by other users. On a system with a permissive umask, the resulting file may be readable by other local accounts or processes. A user-controlled `save_path ...[truncated 1834 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
weiyun_skills/client.py:1343
Finding

Unvalidated Remote Names Permit Path Traversal During Recursive Folder Downloads

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (74)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 68)May include surrounding context.

md
python weiyun_skills/main.py search "报告"

# Delete a file (to recycle bin)
python weiyun_skills/main.py delete /云端目录/old_file.pdf

# Move a file
python weiyun_skills/main.py move /源路径/file.pdf /目标路径/

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill advertises broad authentication and cloud-management capabilities while including unrelated/nonsensical trigger text, which raises trust and routing concerns in an agent ecosystem. Overbroad or misleading descriptions can cause the agent to invoke this skill in inappropriate contexts, increasing the chance of unintended credential handling or file transfer.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill advertises broad authentication and cloud-management capabilities while including unrelated/nonsensical trigger text, which raises trust and routing concerns in an agent ecosystem. Overbroad or misleading descriptions can cause the agent to invoke this skill in inappropriate contexts, increasing the chance of unintended credential handling or file transfer.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains overly broad phrases like 'cloud storage' and generic file-management terms, which can cause the agent to invoke this skill for ordinary requests outside its intended scope. Because the skill can handle authentication material and perform upload/download/delete actions, accidental routing materially increases security risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The examples explicitly tell users to paste live authentication cookies into CLI/Python arguments as plain text. This exposes secrets via shell history, process listings, logs, transcripts, and agent context, enabling account takeover if captured.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 264)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 303)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 306)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 309)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 382)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 383)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 419)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 420)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 423)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 509)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 510)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 543)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 575)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 608)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 640)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 672)May include surrounding context.

md
> python weiyun_skills/main.py <command> [args] [options]

Static analysis

No suspicious patterns detected.