Back to skill

Security audit

charmia-test-0428-01

Security checks for vulnerabilities and agentic risk

Overview

This WeChat Pay payment-integration skill is mostly documentation, but it needs review because it tries to control the agent too broadly and includes unsafe HTTP callback examples.

Install only if you are comfortable with a skill that can steer payment-integration conversations strongly. Keep its use scoped to WeChat Pay delegated-deduction work, prefer HTTPS-only callback URLs in production, validate signatures and idempotency, and treat charge/refund/contract-termination examples as high-impact financial operations requiring human review before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:12
Finding

Session-Wide Workflow and Response Hijacking

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/1-商户/接入指南/回调处理.md:27
Finding

Plain-HTTP Payment Callback URLs Encouraged by Documentation and Examples

Content
View full analysis
http://yoursite.com/wxpay.html ``` The service-provider signing example also incorporates the plaintext callback URL: ```text notify_url: http://yoursite.com/wxpay.html ``` ```text + "¬ify_url=http://yoursite.com/wxpay.html" ``` ### Technical Analysis Allowing and demonstrating plaintext HTTP normalizes an insecure transport configuration for payment callbacks. Although V2 callback signature verification can protect message authenticity when correctly implemented, it does not provide transport confidentiality or availability. An attacker with a network interception position may: - Observe payment callback metadata transmitted over HTTP. - Capture valid signed callback messages and attempt replay against a weakly protected endpoint. - Drop or delay notifications, causing inconsistent local order state. - Modify traffic and responses, creating retry storms or callback-delivery failures. - Exploit implementations that fail to perform strict signature verification, timestamp validation, replay protection, or idempotency checks. The risk is amplified because the examples are directly copyable and may be carried into production configurations without further review. ### Attack Path 1. A developer copies the documented `http://` callback URL pattern into an integration. 2. The production paymen ...[truncated 1328 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (48)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- 服务商模式 → [📄 服务商模式排障手册](./references/2-服务商/问题排查/排障手册.md)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example URL includes a URL-encoded notify_url using plain HTTP (http://www.qq.com/test/papay) for asynchronous callback delivery. Callback endpoints for payment signing flows can carry sensitive status data and are susceptible to interception or tampering if served over HTTP, and the document does not warn readers against this insecure example.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file explains that payment and代扣协议签约 are completed together and that WeChat will asynchronously notify notify_url and contract_notify_url, which implies handling payment results and contract-signing data. However, the description does not include any user-facing warning about the privacy, data-handling, or operational impact of processing payment and signing callbacks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents a destructive business operation: terminating a merchant-user contract. While it explains when to call the interface, it does not include any explicit user warning about the irreversible or user-impacting nature of the action, such as loss of the signed service relationship or the need to verify authorization before termination.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document explains how to download transaction bills that include transaction details and user identifiers, but it does not warn that the returned CSV contains sensitive financial and personal data requiring controlled handling. In a payment integration skill, omission of data-classification, access-control, storage, and redaction guidance can lead developers to export, share, or retain bill data insecurely, increasing risk of privacy breaches and compliance violations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents a close-order API, which can affect transaction handling and prevent further processing of the original order. While it explains usage scenarios and timing constraints, it does not explicitly warn users that closing an order is an operationally impactful action that should be performed only after confirming the order is unpaid and no longer intended for use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents an API that applies扣款/automatic charging and gives operational rules for when charges execute, but it does not include a clear user-facing warning that invoking this operation can directly debit end-user funds. Under the markdown-specific SQP-2 criteria, behaviors affecting user data or system integrity should be accompanied by warnings, and charging a user is a safety-critical financial action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file is markdown, so SQP-2 applies. The document explains how to perform '申请解约' and presents request methods, but it does not include any user-facing warning or caution that the action will terminate a contract and may affect billing or service continuity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a markdown file, so SQP-2 applies. The document explains how to invoke a refund API and notes business constraints, but it does not include any explicit user warning that initiating refunds changes financial records and may result in money being returned to customers.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/产品选型/产品介绍.md (reported line 68)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/1-用户签约/APP纯签约.md (reported line 19)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/1-用户签约/H5纯签约.md (reported line 17)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/1-用户签约/H5纯签约.md (reported line 30)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/1-用户签约/公众号纯签约.md (reported line 15)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/1-用户签约/公众号纯签约.md (reported line 31)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/1-用户签约/支付中签约.md (reported line 14)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/2-代扣扣款/申请扣款.md (reported line 15)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/2-代扣扣款/预扣费通知.md (reported line 16)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/3-协议解约/申请解约.md (reported line 15)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/4-订单协议查询/查询签约关系.md (reported line 15)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/4-订单协议查询/查询订单.md (reported line 14)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/5-退款流程/查询退款.md (reported line 14)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/5-退款流程/申请退款.md (reported line 13)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/6-订单关单对账/下载交易账单.md (reported line 14)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/1-商户/示例代码/6-订单关单对账/关闭订单.md (reported line 19)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/1-商户/接入指南/签名与验签规则.md:201

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/2-服务商/接入指南/签名与验签规则.md:197