Back to skill

Security audit

Wechat Quick Setup

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local WeChat Mini Program scaffold generator, but it generates sensitive cloud-function templates with unsafe defaults and little warning before deployment.

Install only if you understand it is a prototype scaffold generator. Do not deploy the generated cloud functions unchanged for real users, payments, orders, messages, uploads, or databases; add authentication, authorization, allowlists, validation, quotas, logging, and payment verification first. Prefer a pinned installer version and use a sandbox Tencent Cloud environment while reviewing the generated files.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (8)

T09 · Insecure Skill Coding Practices

Error
Location
generate-function.js:104
Finding

Unrestricted Caller-Controlled Database Operations

Content
View full analysis
{ const { action, collection, data, id, where } = event switch (action) { case 'create': return await db.collection(collection).add({ data }) case 'read': if (id) { return await db.collection(collection).doc(id).get() } return await db.collection(collection).where(where || {}).get() case 'update': return await db.collection(collection).doc(id).update({ data }) case 'delete': return await db.collection(collection).doc(id).remove() default: return { error: 'Invalid action' } } } ``` ### Technical Analysis The generated cloud function accepts the database collection, operation, record identifier, query, and record data directly from the invoking client. It does not authenticate the caller, derive identity through `cloud.getWXContext()`, restrict accessible collections, enforce ownership, or validate the supplied data. Cloud functions commonly execute with permissions exceeding those granted to the Mini Program client. Consequently, database security rules applicable to direct client access may not prevent abuse through this function. ### Attack Path 1. A developer generates and deploys the `crud` cloud function. 2. An attacker invokes the function through the Mini Program cloud API. 3. The attacker sets `collection` to a sensitive collection such as `users` or `orders`. 4. The attacker uses `action: "read"` with an empty filter to retrieve records. 5. The attacker can subsequently submit `update` or `delete` with selected record identifiers. ### Impact Assessment An unauthenticated or ordinary application user may gain read and write access to arbitrary application collections. Depending on deployed database ...[truncated 135 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
generate-function.js:47
Finding

Client-Controlled Payment Amount and Order Identifier

Content
View full analysis
{ const { orderId, totalFee } = event const wxContext = cloud.getWXContext() const res = await cloud.cloudPay.unifiedOrder({ outTradeNo: orderId, spbillCreateIp: '127.0.0.1', totalFee: totalFee * 100, envId: cloud.DYNAMIC_CURRENT_ENV, functionName: 'payCallback', nonceStr: Math.random().toString(36).substr(2), tradeType: 'JSAPI' }) return res } ``` ### Technical Analysis The payment amount and merchant order number are accepted directly from an untrusted client request. The function does not retrieve an authoritative order from the database, verify that the authenticated caller owns the order, check its status, or calculate the payable amount from trusted product data. The presence of `wxContext` does not provide protection because it is not used for authorization. The nonce is also generated with `Math.random()`, which is not a cryptographically secure random source. ### Attack Path 1. An attacker identifies or creates a valid order. 2. The attacker directly invokes the payment cloud function. 3. The attacker supplies the order identifier but replaces `totalFee` with a smaller value. 4. The cloud function passes the attacker-controlled amount to the payment API. 5. If downstream order fulfillment relies only on a successful payment callback without authoritative amount reconciliation, the order could be fulfilled after underpayment. ### Impact Assessment Attackers may attempt to underpay for products, reuse or collide with order identifiers, pay against another user's order, or trigger inconsistent payment state. Successful exploitation could cause direct financial loss and corruption of order and payment records. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
generate-function.js:70
Finding

Unauthorized Subscription Message Dispatch

Content
View full analysis
{ const { touser, templateId, page, data } = event const res = await cloud.openapi.subscribeMessage.send({ touser, templateId, page, data }) return res } ``` ### Technical Analysis The generated function forwards all message parameters from the client to the privileged subscription-message API. It does not verify the caller, bind the recipient to an authorized user, restrict template identifiers or destination pages, validate message fields, or apply rate limits. ### Attack Path 1. A developer deploys the generated subscription function. 2. An attacker obtains or guesses a recipient OpenID accepted by the application. 3. The attacker invokes the cloud function with the selected `touser`, `templateId`, `page`, and `data`. 4. The privileged cloud function sends the requested message using application credentials. 5. The attacker repeats the request to consume messaging quotas or send unauthorized content. ### Impact Assessment The function may be abused to send messages to unauthorized recipients, distribute misleading content, consume service quotas, and damage the application's reputation. Abuse could also result in platform enforcement against the application. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
generate-function.js:87
Finding

Unrestricted Cloud Storage Upload

Content
View full analysis
{ const { cloudPath, fileContent } = event const res = await cloud.uploadFile({ cloudPath, fileContent: Buffer.from(fileContent, 'base64') }) return res } ``` ### Technical Analysis The client controls both the cloud storage destination and the complete base64-encoded file content. The function provides no authentication, ownership checks, path restrictions, file-size limits, content-type validation, quotas, collision protection, or content inspection. Decoding the complete request into a `Buffer` can also consume substantial function memory before any storage operation occurs. ### Attack Path 1. An attacker invokes the deployed upload function. 2. The attacker supplies a path associated with another user or a predictable existing object. 3. The attacker supplies arbitrary or excessively large base64 data. 4. The function decodes and uploads the content under privileged cloud credentials. 5. The attacker repeats the operation to overwrite objects, store prohibited content, consume memory, or exhaust storage quotas. ### Impact Assessment Attackers may write arbitrary cloud objects, overwrite predictable paths, consume storage and function resources, incur service costs, or use the application's storage to host unwanted content. Large requests may cause memory exhaustion and denial of service. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
generate-function.js:24
Finding

User Record Mass Assignment Can Override Trusted Identity Fields

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
init.js:201
Finding

Project Name Allows Filesystem Path Traversal

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
generate-function.js:169
Finding

Unsafe Source-Code Substitution Enables Generated JavaScript Injection

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Installation Instructions Execute a Mutable Latest Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The supplied code is a simple Node.js script that accepts a page type argument and writes .js/.wxml/.wxss/.json files for one of three predefined pages. While this is related to code generation for a WeChat Mini Program, it materially falls short of the declared description. There is no logic for creating cloud functions, configuring backend resources, wiring project-wide settings, or producing a complete mini-program scaffold. The primary behavior is much narrower than advertised, so the description does not accurately represent the actual code chunk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill promotes generation of sensitive cloud functions such as login, payment, user management, database access, and file upload without any warning about authentication, authorization, secret handling, data exposure, or billing consequences. In this context, users may deploy insecure scaffolding into production-like Tencent Cloud environments and expose account data or backend operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install command uses npx clawhub@latest, which fetches and executes the latest published package version at runtime. This creates a supply-chain risk: users may unknowingly run changed or compromised code in the future, and the skill provides no pinning, checksum, or review guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instructions explicitly initialize and configure Tencent Cloud resources but omit any warning that these steps may create, modify, or incur cost in a remote cloud environment. In a cloud-setup skill, that omission is more dangerous because users are encouraged to run setup commands that can alter live infrastructure without understanding the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The generated CRUD cloud function exposes create/read/update/delete operations based entirely on untrusted event input, with no authentication, authorization, collection allowlist, or confirmation logic. In this context, the delete path is especially dangerous because any caller able to invoke the function could delete arbitrary documents by ID, turning the template into an insecure direct object reference/admin-function pattern rather than a mere UX issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code template includes a cancelOrder action that immediately invokes updateOrder to mark an order as cancelled, but there is no confirmation prompt, user-facing warning, or inline disclosure about the destructive state change. Because this generator writes that behavior into produced page code, users of the generated page receive no warning before an order is cancelled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains user-facing natural-language strings entirely in Chinese, including the usage/help output shown to the user. The file does not offer any language or locale choice, and there is no indication that the skill is intentionally limited to a China-specific or Chinese-only context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

Comments and CLI help/output are written exclusively in Chinese, including usage instructions and status/error messages. This imposes a specific language on users without opt-in or an alternative locale, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file's comments, CLI help text, and generated UI strings are all hard-coded in Chinese, and there is no indication that the skill is region-specific or that users can opt into this locale. This creates a natural-language locale policy issue because the skill imposes a specific language by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.