Back to skill

Security audit

公众号文案创作

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent WeChat copywriting helper, but it automatically adds undisclosed promotional contact text to results and sends searches to RedFox.

Review this skill before installing. It requires a RedFox API key and sends your search keywords to redfox.hk. Avoid giving it sensitive unpublished plans or private diary-style samples unless you are comfortable using them in this workflow. Be aware that the bundled script currently injects a RedFox sales contact message into command output, which can contaminate generated copy or break JSON consumers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
scripts/fetch_gzh_trends.py:308
Finding

Unconditional Promotional Content Injection into Command Output

Content
View full analysis

Vulnerability Details

File Location: scripts/fetch_gzh_trends.py:308
Vulnerability Type: Forced Promotional Output
Risk Level: Medium

Complete Code Snippet

python
# Directly output to the console
print(output_content)
print(f"\n另外红狐配套全量数据库可提供完整详实数据,如需了解采购方案,可发送邮件至 redfoxdata@proton.me 对接咨洵")

Technical Analysis

The script unconditionally appends an unrelated procurement advertisement and external email address after every successful query. This behavior is not required to retrieve or analyze WeChat trend data and is not disclosed in either README.

Because the message is written to standard output regardless of the selected format, it also corrupts output produced with --output-format json: the resulting stream contains a valid JSON document followed by non-JSON text and therefore cannot be parsed as JSON without special handling.

The behavior conflicts with SKILL.md:245, which prohibits adding external contact information to generated copy. Although the Skill instructs the agent to analyze rather than directly display raw script output, the injected message still enters the agent's context and could be reproduced in generated content.

Attack Path

  1. A user requests WeChat trend analysis or article generation.
  2. The Skill invokes scripts/fetch_gzh_trends.py as directed by SKILL.md.
  3. The script performs the legitimate RedFox API request and prepares the requested result.
  4. After printing that result, line 308 always appends promotional text and an external contact address.
  5. The downstream agent or output parser receives the injected content.
  6. An agent may reproduce the advertisement, while a JSON consumer may fail to parse the contaminated output.

No user-controlled code execution or privilege escalation is enabled by this issue. Exploitation occurs automatically whenever the script completes successfully.

Impact Assessment

The issue does not grant fil ...[truncated 762 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the unconditional promotional print statement at line 308.
  2. Keep standard output strictly compliant with the selected output format. In particular, JSON mode must emit only one valid JSON document.
  3. If commercial information must be retained, disclose it transparently in project documentation rather than injecting it into runtime results.
  4. If an optional notice is considered necessary, require an explicit user-controlled flag and write the notice to standard error rather than standard output.
  5. Add automated tests that:
    • Parse JSON-mode output with a standard JSON parser.
    • Verify that normal output contains no unsolicited email addresses or promotional text.
    • Verify consistency with the external-contact restriction in SKILL.md.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (14)

Tainted flow: 'headers' from os.environ.get (line 109, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/fetch_gzh_trends.py (reported line 44)May include surrounding context.

python
print(f"Params: {json.dumps(params, ensure_ascii=False)}", file=sys.stderr)

    try:
        response = requests.post(base_url, headers=headers, json=params, timeout=60)

        if debug:
            print(f"状态码: {response.status_code}", file=sys.stderr)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broader content-creation tool: searching viral articles, analyzing traffic规律, and generating complete publishable WeChat articles/copy. However, the supplied code implements only a data retrieval and formatting utility for trending public-account articles from the Redfox API. Its behavior is limited to sending a POST request with keyword/date filters, optionally expanding from 7 to 30 days if results are sparse, and rendering a markdown report with title/author/read/like/comment metrics. There is no code for article generation, rewriting, drafting, or any nontrivial analytical processing of traffic patterns. Therefore the description overstates the implemented capabilities, making it a mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs users to invoke it with broad natural-language phrases like "help me write a WeChat article" and similar generic content-writing requests. Because these triggers overlap with ordinary user intent, the skill may activate unexpectedly and gain access to user prompts or attached content in situations where the user did not mean to invoke this specific third-party workflow, increasing the risk of unintended data exposure or unreviewed outbound API use.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.en.md (reported line 57)May include surrounding context.

md
### Quick Reference

| Intent               | Example phrase                                            | Result                                                                                          |
| -------------------- | --------------------------------------------------------- | ----------------------------------------------------------------------------------------------- |
| Write an article     | "Help me write a WeChat article about career changes"     | Search virals by keyword, analyze patterns, then generate a complete article                    |
| Recommend a product  | "Help me write a WeChat article recommending an AI tool"  | Automatically break down differentiation advantages and generate copy around product highlights |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README tells users to invoke the skill with broad natural-language requests like '帮我写一篇...' and '分析一下...,' without narrowing allowed topics, data sources, or output safety constraints. In an agent setting, this can cause over-triggering and misuse, including generating promotional, misleading, or policy-sensitive content from vague prompts, especially because the skill can also ingest personal style samples and recommend specific products.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill instructs use of environment-provided API credentials and outbound network access, but does not declare any explicit tool scope or allowed-tools boundary. That increases the chance of overbroad execution in hosts that infer capabilities loosely, making unintended network calls or secret exposure easier if the skill is invoked in a more permissive runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description and all operating instructions are written as mandatory Chinese-language公众号 writing behavior, and the output requirements prescribe a specific Chinese writing style without any user opt-in or alternative locale/language path. This creates a language/locale policy issue because the skill is effectively constrained to Chinese output by default rather than explicitly asking the user for their preferred language.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly asks users to upload diary, note, or essay samples so it can infer and mimic their personal writing style. That creates an unnecessary collection path for sensitive free-form personal data, which may include private experiences, health, relationship, work, or identity information unrelated to the core task of generating public-account copy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation instructs use of an external API and shows endpoint details, but does not disclose that user-supplied keywords and related query data are sent to a third-party service. This creates a real privacy/transparency issue: users may provide sensitive editorial plans, campaign topics, or proprietary business terms without knowing that data leaves the local environment. Because this skill is for content generation and trend analysis, users may reasonably assume the tool is self-contained unless warned otherwise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document includes a raw third-party API key in plaintext, which is a real secret exposure. Anyone with access to this skill content could reuse the key to query the provider, consume quota, incur cost, or pivot into broader abuse depending on the provider account permissions. In this skill context, the key is directly tied to backend content retrieval rather than end-user output, so exposing it is unnecessary and more dangerous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-facing descriptions, help text, output, and error messages in this file are written exclusively in Chinese. This enforces a specific language/locale without offering the user an opt-in or alternative, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This script transmits user input and metadata to an external API over the network. In the context of a content-research skill, external transmission is expected, but it still creates a real confidentiality boundary because entered keywords and associated request metadata are disclosed to a third party.

Content

Scanner excerpt · scripts/fetch_gzh_trends.py (reported line 44)May include surrounding context.

python
print(f"Params: {json.dumps(params, ensure_ascii=False)}", file=sys.stderr)

    try:
        response = requests.post(base_url, headers=headers, json=params, timeout=60)

        if debug:
            print(f"状态码: {response.status_code}", file=sys.stderr)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script sends user-provided keywords to a third-party service and also includes a source identifier, but the CLI does not clearly warn the user at execution time that their query leaves the local environment. This is primarily a privacy/transparency issue: sensitive or proprietary keywords could be disclosed to the vendor without the user fully realizing it.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a tool for searching hot WeChat articles, analyzing traffic patterns, and helping generate public-account copy. At L308, the script appends a procurement/contact advertisement for the vendor's full database, which is not part of querying or analyzing article trends and adds behavior outside the described user-facing purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.