Back to skill

Security audit

Publish to WeChat

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate WeChat/LivePage publishing helper, but it uploads chosen content to a third-party service and can enable sharing, analytics, feedback, and form collection.

Before installing, make sure you trust the LivePage/24haowan service and only publish artifacts you are comfortable uploading there. Confirm the target content, visibility setting, passcode/public access, replay/engagement tracking, forms, and any payment QR details before sharing a link.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger description is very broad and includes common phrases like 'give me a link' and 'who read it', which can match many unrelated user requests. That increases the chance the agent invokes this skill in the wrong context, leading to unintended publishing, sharing, or exposure of user content to an external service.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The body adds more vague activation phrases such as 'save this', 'make it one page', and 'generate a link for others', again without strong disambiguation. In a skill that uploads content and manages sharing, ambiguous activation can cause accidental data transfer, privacy violations, or unexpected use of third-party publishing infrastructure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language instructions and all user-facing phrasing in the skill are written entirely in Chinese, with no indication that the user may choose another language. This can violate language/locale policy when a skill implicitly constrains interaction language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.