Back to skill

Security audit

微信搜索

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a real WeChat video-search helper, but it handles a reusable API token unsafely and overstates some supported search types.

Install only if you are comfortable sending WeChat search keywords and your GUAIKEI_API_TOKEN to www.guaikei.com. Rotate the token if you have already used this version, and be aware that only video search is implemented despite broader article/image claims.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/api/video.js:15
Finding

Reusable API Token Exposed in URL Query Strings

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a substantial mismatch between the claimed WeChat article/video/image search capability and the detected implementation characteristics, which reportedly lack actual search logic and instead include generic infrastructure. Capability mismatches are dangerous because they can conceal non-obvious behavior, prevent meaningful user consent, and indicate that the published description is not sufficient to assess what the skill really does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a substantial mismatch between the claimed WeChat article/video/image search capability and the detected implementation characteristics, which reportedly lack actual search logic and instead include generic infrastructure. Capability mismatches are dangerous because they can conceal non-obvious behavior, prevent meaningful user consent, and indicate that the published description is not sufficient to assess what the skill really does.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill requires access to an environment variable token (GUAIKEI_API_TOKEN) but does not declare any explicit tool scope or permissions boundary. This creates hidden capability usage, making it harder for a calling platform or reviewer to understand what sensitive data the skill can access and increasing the risk of unintended secret exposure or overbroad execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger conditions are broad enough that the skill may be invoked for generic user requests mentioning WeChat, keywords, or current content, even when the user did not explicitly request this external tool. Overbroad invocation can cause unintended transmission of user queries to a third-party service and unnecessary use of sensitive tokens or external APIs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill emits fixed Chinese-language status and error messages in string literals, which imposes a specific language on users without offering a language choice or documenting a justified locale-specific scope. This matches the language/locale policy violation category for natural-language policy issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript file contains user-facing warning and info messages entirely in Chinese, which imposes a specific language on users without offering a language choice or documenting that the skill is intended only for a Chinese-speaking or region-specific audience. That matches the policy category for language or locale constraints expressed in natural-language content within code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI's help text and multiple status/error messages are fixed in Chinese, which can force a specific language experience on users without opt-in. Under the policy rule, language constraints should either be optional or clearly documented as intentional and justified for a region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill is described entirely in Chinese and is specialized around WeChat content, but it does not state that use is limited to Chinese-language or WeChat-specific contexts, nor does it offer a language/locale choice. This can conflict with a language or locale policy when an agent is expected to adapt to the user's preferred language unless the constraint is explicitly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The package description forces a single language/locale in its user-facing natural-language metadata. Under the policy, language-specific behavior should either offer user opt-in/choice or clearly justify the locale restriction; this manifest provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file’s human-readable guidance appears exclusively in Chinese across the comments, including the top-level description and constant documentation. Under the policy, forcing a specific language without user choice can be a natural-language locale violation, and there is no indication here that the skill is region-specific or intentionally limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The AuthError message is hard-coded in Chinese and directs the user to a WeChat contact, which imposes a specific language and communication channel with no indication that users can choose another locale. Under the stated policy, forcing a language without opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This file contains natural-language strings exclusively in Chinese, including the JSDoc description and the thrown error message. The stated policy flags language or locale constraints when a skill forces a specific language without offering user choice or documenting why that locale is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This utility module presents user-facing text entirely in Chinese, including the banner title and comments describing its behavior. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation when no language choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript file contains natural-language comments and user-visible validation errors entirely in Chinese, such as the messages printed on invalid keywords. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy concern, and no language choice or region-specific rationale is present in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code persists the full search output to disk via log.taskWrite, which is a file-write operation covered by the missing-warning rule for code files. Although the function docstring mentions '保存日志', there is no explicit runtime disclosure near the write that search results will be stored locally, so users may not realize their query/results are being saved.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.