Back to skill

Security audit

wechat-publisher

Security checks across malware telemetry and agentic risk

Overview

This WeChat management skill appears legitimate, but its delete capabilities can remove account content without clearly documented confirmation safeguards.

Install only if you intend to let the agent operate a WeChat Official Account. Before using delete or publish actions, require the agent to show the exact target IDs/titles and wait for explicit confirmation. Avoid using it with sensitive drafts or media unless sending that data to WeChat is intended.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill exposes destructive operations such as deleting drafts, published articles, materials, comments, and replies without any explicit user-facing warning, confirmation guidance, or indication that these actions are irreversible. In an agent setting, this increases the risk of accidental or overly broad invocation leading to content loss or disruption of a live WeChat account.

Missing User Warnings

Low
Confidence
81% confidence
Finding
The skill advertises publication, material management, statistics, and comment-management features that necessarily transmit article content, media, identifiers, and analytics queries to external WeChat APIs, but it does not clearly warn users about that data flow. This can cause unintended disclosure of sensitive business content or account data when the tool is used in automated environments.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.