Back to skill

Security audit

公众号投资博主蒸馏器

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its stated WeChat article-distillation purpose, but it has review-worthy side effects around automatic package installation, credential handling, and unsafe local file paths.

Review before installing. Use a disposable virtual environment, set REDFOX_API_KEY via environment or a protected secret store rather than `--api-key`, avoid untrusted author/account strings, and expect the skill to fetch and locally store full WeChat article content plus engagement data. Do not run it where automatic package installation or local credential-file lookup is unacceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/distill.py:999
Finding

Path Traversal Through Unsanitized Author and Account Names

Content
View full analysis
Remediation
View remediation
str: if not value or not SAFE_NAME.fullmatch(value): raise ValueError(f"Invalid {field}") return value ``` 2. Alternatively, generate filesystem-safe identifiers independently from display names: ```python import hashlib safe_id = hashlib.sha256(author_name.encode("utf-8")).hexdigest()[:24] ``` 3. Resolve and verify every constructed path before reading or writing: ```python def confined_path(base: Path, filename: str) -> Path: base = base.resolve() candidate = (base / filename).resolve() if not candidate.is_relative_to(base): raise ValueError("Path escapes the output directory") return candidate ``` 4. Reject values containing `/`, `\`, `..`, drive prefixes, NUL characters, or absolute paths. 5. Apply the same validation to all profile, statistics, article, cache, task, and report paths. Do not protect only the primary output file. 6. Where overwriting is unnecessary, use exclusive creation or explicit overwrite confirmation to reduce accidental data loss. ]]>

T08 · Insecure Dependencies

Note
Location
scripts/distill.py:63
Finding

Automatic Installation of an Unpinned Dependency

Content
View full analysis
Remediation
View remediation
``` 3. For reproducible deployments, use a lock file and hash verification: ```text requests== --hash=sha256: ``` 4. Recommend installation into an isolated virtual environment instead of modifying the active system or user environment. 5. Document the expected package index and discourage untrusted mirrors. In controlled deployment environments, install dependencies during a reviewed build phase rather than at Skill runtime. 6. Replace `os.system` with a non-shell subprocess call if an explicit installer utility is retained: ```python subprocess.run( [sys.executable, "-m", "pip", "install", "--require-hashes", "-r", requirements], check=True, ) ``` This does not replace the need for user consent, version pinning, and integrity verification. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/distill.py:1335
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis
环境变量 > 配置文件。未配置返回空字符串。""" if cli_key: return cli_key env_key = os.environ.get(ENV_KEY) if env_key: return env_key if CONFIG_FILE.exists(): try: data = json.loads(CONFIG_FILE.read_text(encoding="utf-8")) key = data.get("api_key") or data.get("REDFOX_API_KEY") if key: return key except (json.JSONDecodeError, OSError): pass return "" ``` ```python # scripts/gzh.py:302-313 key = get_api_key(api_key) if not key: error("未配置 API Key,请设置环境变量 REDFOX_API_KEY=ak_xxxxxxxx") error("获取 Key: https://redfox.hk/settings/api-keys?source=clawhub") return [] session = requests.Session() session.headers.update({ "Content-Type": "application/json", "X-API-Key": key, }) ``` ### Technical Analysis The RedFox API key is legitimately required for the declared article-collection functionality, and the code sends it only to the documented HTTPS RedFox endpoints. No unrelated credential exfiltration was identified. The security issue is the optional `--api-key` interface. Secrets supplied as process arguments may be recorded in shell history, process inspection interfaces, orchestration metadata, diagnostic reports, CI logs, command audit logs, or monitoring systems. CLI arguments therefore provide weaker ...[truncated 1367 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill markets itself as a style-distillation and analysis tool, but the documented behavior also includes external data collection via redfox.hk and appears not to implement much of the promised analysis. This mismatch is dangerous because users may authorize the skill under false assumptions, while it performs third-party data retrieval and storage of article corpora and profile data that materially changes the privacy and trust risk.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

The script executes a shell command to install a package during an environment check, which introduces command execution behavior unrelated to the core text-analysis task. Even though sys.executable is usually locally controlled, invoking the shell expands attack surface and can lead to unintended command execution, package supply-chain risk, or unsafe behavior in automated environments.

Content

Scanner excerpt · scripts/distill.py (reported line 68)May include surrounding context.

python
info("requests 已就绪")
    except ImportError:
        warn("缺少 requests,正在安装...")
        os.system(f"{sys.executable} -m pip install requests")
        try:
            import requests
            info("requests 安装成功")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README explicitly promotes automatic collection of WeChat public-account articles and automatic generation of local output files, but it does not clearly warn users about data-collection behavior, storage side effects, or the sensitivity of scraped content and engagement metrics. In a skill that gathers third-party content at scale, lack of upfront disclosure can lead to unintentional collection, retention, or redistribution of data and increases privacy, compliance, and operational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description highlights collecting article bodies, summaries, timestamps, and engagement metrics, then outputting structured reports, but it does not warn users that it is processing and reproducing third-party content and behavioral/engagement data. This omission increases the risk of privacy, copyright, and platform-policy issues because users may invoke the skill without understanding that it gathers and republishes external content-derived data at scale.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises very broad natural-language triggers such as '用某博主的风格分析一下…' and '蒸馏公众号…' without clear boundaries on when the skill should activate or what inputs are in scope. In an agent setting, this can cause over-triggering on ambiguous user requests and lead to unintended collection, transformation, or reproduction of third-party content and persona mimicry beyond what the user explicitly intended.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill requests or implies powerful capabilities (environment access, file read/write, network, shell) but does not declare any explicit tool scope or permissions boundary. That makes it easier for an agent runtime to grant broader access than users expect, enabling data exfiltration, arbitrary filesystem writes, or command execution during a workflow that appears to be simple content analysis.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad enough to match generic investing or style-analysis requests, which can cause the skill to activate in contexts where the user did not intend automated scraping, profiling, or external API usage. In an investment-related skill, accidental invocation is more sensitive because it may collect third-party content, incur paid API charges, or generate advice-like outputs under a simulated persona.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly states that AI will automatically collect blogger background materials, milestone events, mentors, and social interaction data via web search, but it does not present a clear privacy warning or consent checkpoint about this profiling behavior. That is risky because the skill goes beyond processing user-supplied articles and moves into aggregating personal or reputational data about third parties, which raises privacy, compliance, and misuse concerns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire markdown template is written in Chinese and defines all output headings, labels, and placeholders in Chinese, which effectively constrains the skill's generated content to a specific language. The file does not indicate that this is optional, user-selected, or justified as a region-specific template, so it appears to impose a language/locale choice by default.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatically modifying the host environment during a routine check exceeds the minimum privileges needed for this skill and violates user expectations. In agent or CI contexts, this can silently install code from external sources and create persistence or trust-boundary issues beyond simple analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Installing packages automatically via a shell command without explicit confirmation creates an unsafe setup path and increases supply-chain and execution risk. In unattended runs, users may not realize the script is changing the environment or executing fetched package code.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill persists full fetched article contents to local disk, which expands data retention and privacy risk beyond immediate processing. If the host is shared, compromised, or backed up, sensitive or proprietary source data may be exposed long after the analysis completes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Writing fetched article data to disk without a clear upfront warning reduces transparency around local persistence and can surprise users about where source content is stored. In this skill's context, raw article archives may contain large amounts of third-party content and metadata, increasing confidentiality and retention concerns.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script reads a sensitive API key and partially echoes it to stdout, creating unnecessary credential exposure in logs, terminals, or shared execution transcripts. While only a prefix is shown, partial secrets can still aid correlation, debugging leaks, or operational disclosure, and this capability is not essential to producing a style profile.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Manifest 描述的核心输出是结构化风格画像 profile,但实现中还会写入统计数据 JSON、数据底稿 Markdown、蒸馏任务 Markdown、以及后续校验报告等多种文件。这些中间和辅助输出可能有助于工作流,但实际行为范围明显宽于“输出结构化 profile”的表述。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.