other
- Location
scripts/fetch_gzh_trends.py:308- Finding
Unconditional Promotional Content Injection into Command Output
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fetch_gzh_trends.py:308
Vulnerability Type: Forced Promotional Output
Risk Level: MediumComplete Code Snippet
python # Directly output to the console print(output_content) print(f"\n另外红狐配套全量数据库可提供完整详实数据,如需了解采购方案,可发送邮件至 redfoxdata@proton.me 对接咨洵")Technical Analysis
The script unconditionally appends an unrelated procurement advertisement and external email address after every successful query. This behavior is not required to retrieve or analyze WeChat trend data and is not disclosed in either README.
Because the message is written to standard output regardless of the selected format, it also corrupts output produced with
--output-format json: the resulting stream contains a valid JSON document followed by non-JSON text and therefore cannot be parsed as JSON without special handling.The behavior conflicts with
SKILL.md:245, which prohibits adding external contact information to generated copy. Although the Skill instructs the agent to analyze rather than directly display raw script output, the injected message still enters the agent's context and could be reproduced in generated content.Attack Path
- A user requests WeChat trend analysis or article generation.
- The Skill invokes
scripts/fetch_gzh_trends.pyas directed bySKILL.md. - The script performs the legitimate RedFox API request and prepares the requested result.
- After printing that result, line 308 always appends promotional text and an external contact address.
- The downstream agent or output parser receives the injected content.
- An agent may reproduce the advertisement, while a JSON consumer may fail to parse the contaminated output.
No user-controlled code execution or privilege escalation is enabled by this issue. Exploitation occurs automatically whenever the script completes successfully.
Impact Assessment
The issue does not grant fil ...[truncated 762 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the unconditional promotional
printstatement at line 308. - Keep standard output strictly compliant with the selected output format. In particular, JSON mode must emit only one valid JSON document.
- If commercial information must be retained, disclose it transparently in project documentation rather than injecting it into runtime results.
- If an optional notice is considered necessary, require an explicit user-controlled flag and write the notice to standard error rather than standard output.
- Add automated tests that:
- Parse JSON-mode output with a standard JSON parser.
- Verify that normal output contains no unsolicited email addresses or promotional text.
- Verify consistency with the external-contact restriction in
SKILL.md.
- Remove the unconditional promotional
