Back to skill

Security audit

微信文章排版预览

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent as a WeChat article preview formatter, but its helper scripts can expose local files or run unsafe preview content when given untrusted HTML or image paths.

Review before installing if you will process HTML or image paths from other people. Use it only with trusted article drafts and trusted local assets, avoid absolute or parent-directory image paths, avoid custom theme/style JSON from untrusted sources, and inspect generated previews before copying or publishing. The behavior does not look intentionally malicious, but the helper scripts need tighter input validation and sanitization.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/inline_images.py:27
Finding

Path Traversal Allows Arbitrary Local File Embedding

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_preview.py:120
Finding

Unsanitized Template Substitution Enables Script Execution in Generated Previews

Content
View full analysis
{{ARTICLE_TITLE}} ``` ```html {{LLM_CONTENT_PLACEHOLDER}} ``` ```html ``` ### Technical Analysis The generator performs context-insensitive string substitution for four security-sensitive data types: - The article title is inserted into an HTML `` context without HTML escaping. - Article content is inserted directly into the document DOM without sanitization. - Custom theme data is inserted into an executable JavaScript context without JSON parsing, schema validation, or safe serialization. - Custom style data is inserted into the same executable JavaScript context without validation or safe serialization. As a result, article HTML can contain executable elements or attr ...[truncated 3054 chars]
Remediation
View remediation
... ``` Parse the text content after validating that embedded `<` characters have been escaped. 8. Add a restrictive Content Security Policy. Refactor inline scripts and event handlers so the policy can disallow unapproved script execution and network destinations. 9. Do not automatically offer to open a preview until all untrusted title, content, theme, and style inputs have passed validation. 10. Sanitize or validate HTML before restoring it through `innerHTML`, or store a structured representation and rebuild the approved DOM safely. 11. Add regression tests for: - ...[truncated 217 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose centers on HTML article creation and formatting for WeChat, including normalization, theming, preview generation, and preparing article body content. The actual code does none of those things. Instead, it implements a local image-to-base64 converter for cover or other images. While such a utility could conceivably support article preparation, that capability is not disclosed in the description, and the code chunk’s primary purpose is materially different from the declared article-processing functionality. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/template-parts/layout.html (reported line 55)May include surrounding context.

html
</div>

  <main class="preview-stage">
    <!-- 
      重要提示:
      LLM 在生成内容时,请将生成的包含 data-role 属性的 HTML 标签放入此 article 容器内。
      无需再生成外层的 html/head/body 结构,也无需重新定义样式。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/template-parts/layout.html (reported line 55)May include surrounding context.

html
</div>

  <main class="preview-stage">
    <!-- 
      重要提示:
      LLM 在生成内容时,请将生成的包含 data-role 属性的 HTML 标签放入此 article 容器内。
      无需再生成外层的 html/head/body 结构,也无需重新定义样式。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs the agent to read and write local files and to invoke scripts that may open previews, but it declares no explicit tool scope or permission boundaries. Without an allowlist, downstream runtimes may grant broader filesystem or network access than users expect, increasing the chance of unauthorized file access or side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction '保留来源语种。中文来源的标题、标签和正文都应保持中文' imposes a language constraint for Chinese-source content. Because the skill does not present this as a user-selectable option or clearly justify it as a region-specific compliance requirement, it can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L07 requires headings to use 'natural Chinese phrasing,' which is a language-specific constraint expressed in natural language. Because the file does not offer a user language choice or explain that the skill is limited to a Chinese-language context, this appears to force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML declares lang="zh-CN" and the visible interface labels are written in Chinese throughout the toolbar. This enforces a specific language/locale in the skill output without any opt-in or documented region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This JavaScript includes hard-coded Chinese error text and UI strings, beginning here and continuing throughout the file, which imposes a specific language on users without any opt-in or locale selection mechanism. That matches the policy-violation category for language or locale constraints in natural-language content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill is presented as an HTML-first article formatter and preview tool for local copy into WeChat. This code performs arbitrary URL fetches for image sources during copy preparation, introducing network access that is not mentioned in the manifest and is not an obvious requirement of a local formatter.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes generating, normalizing, theming, previewing, and preparing WeChat-friendly article HTML. This code implements a full edit mode with mutable content state and local persistence, plus later annotation workflows, which are materially broader capabilities than formatting and preview alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L201 uses the specific Chinese trigger phrase “换个配色” as the only example for the fallback behavior, which embeds a language-specific assumption into the skill guidance. The file does not offer an alternative language choice or explain that the skill is intentionally limited to Chinese-speaking or WeChat-specific users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L23 says headings should be kept natural in Chinese and provides only Chinese examples, which imposes a language preference in the skill's instructions. The file does not indicate that Chinese output is optional, user-selected, or required by a clearly documented region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script displays its confirmation prompt and status/error messages in Chinese only, which imposes a specific language on users without opt-in. This matches the policy concern for locale/language restrictions because the file contains no indication that the skill is intended only for Chinese-speaking users or that alternative language handling is available.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill defaults to creating files under dist/ and may generate preview artifacts as part of normal operation, but it does not require clear prior user consent for filesystem modification. Unexpected writes are a safety issue because they can alter the workspace, overwrite files if paths are changed, or surprise users in automated contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document requires output to be copied into the WeChat Official Account backend, which is a locale/platform-specific constraint expressed in natural language. It does not indicate user opt-in, alternatives, or that this restriction is justified as a region-specific tool, so it may violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code presents the browser-open prompt and several CLI defaults/messages in Chinese, including the interactive confirmation at L135 and the default title/help text around L148-L149, without any opt-in or locale selection. That is a natural-language locale policy concern because the skill fixes one language for user interaction rather than offering a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.