T01 · Skill Instruction Hijacking
- Location
SKILL.md:12- Finding
Session-Wide Workflow and Response Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This WeChat Pay payment-integration skill is mostly documentation, but it needs review because it tries to control the agent too broadly and includes unsafe HTTP callback examples.
Install only if you are comfortable with a skill that can steer payment-integration conversations strongly. Keep its use scoped to WeChat Pay delegated-deduction work, prefer HTTPS-only callback URLs in production, validate signatures and idempotency, and treat charge/refund/contract-termination examples as high-impact financial operations requiring human review before use.
SKILL.md:12Session-Wide Workflow and Response Hijacking
references/1-商户/接入指南/回调处理.md:27Plain-HTTP Payment Callback URLs Encouraged by Documentation and Examples
Referenced artifact was not completely inspected
- 服务商模式 → [📄 服务商模式排障手册](./references/2-服务商/问题排查/排障手册.md)
The example URL includes a URL-encoded notify_url using plain HTTP (http://www.qq.com/test/papay) for asynchronous callback delivery. Callback endpoints for payment signing flows can carry sensitive status data and are susceptible to interception or tampering if served over HTTP, and the document does not warn readers against this insecure example.
This markdown file explains that payment and代扣协议签约 are completed together and that WeChat will asynchronously notify notify_url and contract_notify_url, which implies handling payment results and contract-signing data. However, the description does not include any user-facing warning about the privacy, data-handling, or operational impact of processing payment and signing callbacks.
This markdown file documents a destructive business operation: terminating a merchant-user contract. While it explains when to call the interface, it does not include any explicit user warning about the irreversible or user-impacting nature of the action, such as loss of the signed service relationship or the need to verify authorization before termination.
The document explains how to download transaction bills that include transaction details and user identifiers, but it does not warn that the returned CSV contains sensitive financial and personal data requiring controlled handling. In a payment integration skill, omission of data-classification, access-control, storage, and redaction guidance can lead developers to export, share, or retain bill data insecurely, increasing risk of privacy breaches and compliance violations.
This markdown file documents a close-order API, which can affect transaction handling and prevent further processing of the original order. While it explains usage scenarios and timing constraints, it does not explicitly warn users that closing an order is an operationally impactful action that should be performed only after confirming the order is unpaid and no longer intended for use.
This markdown file documents an API that applies扣款/automatic charging and gives operational rules for when charges execute, but it does not include a clear user-facing warning that invoking this operation can directly debit end-user funds. Under the markdown-specific SQP-2 criteria, behaviors affecting user data or system integrity should be accompanied by warnings, and charging a user is a safety-critical financial action.
This file is markdown, so SQP-2 applies. The document explains how to perform '申请解约' and presents request methods, but it does not include any user-facing warning or caution that the action will terminate a contract and may affect billing or service continuity.
This is a markdown file, so SQP-2 applies. The document explains how to invoke a refund API and notes business constraints, but it does not include any explicit user warning that initiating refunds changes financial records and may result in money being returned to customers.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 项 | 值 |
|---|---|
| 适用对象 | 服务商 |
| 请求 URL | `https://api.mch.weixin.qq.com/pay/downloadbill` |
| 请求方式 | POST |
| 数据格式 | XML(请求)/ CSV 文本(响应成功)/ XML(响应失败) |
Detected: suspicious.exposed_secret_literal