Back to skill

Security audit

Wx Miniprogram Ci

Security checks for vulnerabilities and agentic risk

Overview

This WeChat mini-program CI skill is purpose-aligned, but it needs review because it can deploy remote resources and automatically install and run global tooling.

Install only if you are comfortable with a skill that can upload code and cloud assets to WeChat, uses WeChat CI private key paths, writes a persistent config file in your home directory, and may run npm install -g miniprogram-ci. Prefer running it in a dedicated project environment with least-privilege WeChat CI credentials, review commands before any upload, and consider preinstalling a pinned miniprogram-ci version instead of allowing automatic global installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/wx-miniprogram-ci.js:466
Finding

Automatic Unpinned Global Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: scripts/wx-miniprogram-ci.js, lines 466-476
Vulnerability Type: Supply-chain risk caused by automatic installation of an unpinned global dependency
Risk Level: Medium

Vulnerable Code

javascript
function ensureGlobalMiniprogramCi() {
  const { execSync } = require('child_process');
  try {
    execSync('miniprogram-ci --version', { stdio: 'ignore' });
    log('miniprogram-ci 已全局安装', 'success');
    return true;
  } catch (e) {
    log('miniprogram-ci 未全局安装,正在进行全局安装...', 'info');
    try {
      execSync('npm install -g miniprogram-ci', {
        stdio: 'inherit',
        shell: process.platform === 'win32'
      });

Technical Analysis

The skill automatically runs npm install -g miniprogram-ci when the corresponding executable cannot be found. It does not pin an exact audited version, use a lockfile, verify an integrity digest, or constrain the npm registry.

Consequently, the effective dependency code may change after this skill has been reviewed. npm installation can also execute package lifecycle scripts. Because the dependency is installed globally, such scripts execute with the permissions of the user running the skill and can affect globally accessible files and tooling.

This behavior is also explicitly documented in SKILL.md, lines 80-84:

markdown
初始化环境:
1. 检查是否已全局安装 `miniprogram-ci`
2. 如果未安装则执行 `npm install -g miniprogram-ci`
3. 保持当前脚本作为配置管理和全局 CLI 调用层

Attack Path

  1. The user invokes init, preview, upload, or another command that calls ensureGlobalMiniprogramCi().
  2. The miniprogram-ci --version check fails because the executable is absent, unavailable through PATH, or otherwise cannot execute.
  3. The skill invokes the configured npm client to resolve the current miniprogram-ci package from the active registry.
  4. If the package, registry, package publisher, or dependency chain has been compromised, attacker-controlled installation or lifecycle code e ...[truncated 758 chars]
Remediation
View remediation

Remediation Suggestions

  1. Declare an exact audited miniprogram-ci version in a local package.json; do not use a floating version.
  2. Commit a lockfile containing dependency versions and integrity metadata.
  3. Install dependencies locally with npm ci rather than automatically modifying the global npm environment.
  4. Invoke the project-local executable through a controlled path, such as node_modules/.bin/miniprogram-ci, instead of relying on PATH.
  5. Avoid automatic installation during operational commands. If the dependency is missing, fail safely and provide explicit installation instructions.
  6. Enforce a trusted npm registry and validate the resolved package source and integrity.
  7. Review lifecycle scripts and consider installation controls appropriate to the dependency, such as disabling scripts where compatible.
  8. Run CI tooling under a dedicated, non-privileged account with access limited to the required project, key, and output paths.
  9. If global installation is unavoidable, require explicit user confirmation, pin the exact version, verify it before execution, and never perform the installation with elevated privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
> ⚠️ **注意**:脚本位于 `scripts/wx-miniprogram-ci.js`,可从仓库根目录直接运行:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
> ⚠️ **注意**:脚本位于 `scripts/wx-miniprogram-ci.js`,可从仓库根目录直接运行:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The tool loads ~/.wxmini-ci.config.js with require(), which executes arbitrary JavaScript from a user-controlled path. In addition, --config-dir lets callers redirect that load to another directory, turning configuration parsing into code execution in the context of whoever runs the script.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documents commands for preview, upload, cloud function upload, and cloud storage upload, all of which can modify remote WeChat resources, but it does not prominently warn users that these operations are state-changing and potentially production-impacting. In an agent context, this increases the risk of unintended deployments or uploads if the skill is invoked without explicit confirmation boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code writes configuration values into ~/.wxmini-ci.config.js and the supported keys include privateKeyPath, which is a credential-related setting for CI operations. Although the write is logged, there is no user-facing warning in code comments/help text that configuration changes are persisted to disk and may include sensitive credential references.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes capabilities for WeChat mini-program preview/upload/build and cloud artifact upload, but does not justify modifying the host environment by globally installing software. Here the script checks for miniprogram-ci, then runs npm install -g miniprogram-ci and later invokes the external binary via child processes, adding host-level package management and command execution capability beyond the declared business function.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code runs execSync('npm install -g miniprogram-ci'), which changes the user's global Node.js installation state. While runtime logs indicate installation is occurring, the help text does not clearly warn users in advance that init will execute a global package installation and modify the system environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation instructs users to persist privateKeyPath values in a long-lived config file under the home directory without a clear warning about handling sensitive deployment credentials. While it stores the path rather than the key contents, normalizing persistent credential references can still weaken operational security and make accidental misuse of privileged signing keys more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Natural-language strings throughout the file, including the main banner and help output, are exclusively in Chinese. This forces a specific language experience without opt-in or explanation, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.secret_argv_exposure

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/wx-miniprogram-ci.js:467

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:124