Back to skill

Security audit

Wechat Article Writer

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language WeChat article-writing aid with no executable code, install script, persistence, credential handling, or automatic publishing behavior.

Install this if you want help drafting or revising Chinese WeChat public-account articles. Expect Simplified Chinese style and platform-specific writing advice; for factual, policy, medical, legal, financial, or current-event content, verify sources before publishing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest presents the skill exclusively as a Chinese-language WeChat article writer and optimizer, with no indication that language choice is optional. This can violate language/locale policy expectations when a skill implicitly forces a specific language or locale without offering user choice or documenting the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill reference is written as Chinese-only guidance and does not offer any user language choice or note that the resource is intentionally limited to a Chinese-language context. Under the policy for natural-language violations, forcing a specific language without opt-in can be a locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions and examples exclusively in Chinese, with no indication that the user can opt into another language or that the skill is intentionally limited to a Chinese-language audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire guidance document is written as a Chinese-only platform guardrail and does not indicate that language choice is optional or based on user preference. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file includes a dedicated section titled '中文语感' and another section requiring Chinese full-width punctuation, which together prescribe Chinese-specific language and formatting requirements. Because the file provides these as mandatory review criteria without offering opt-in or stating that the skill is only for Chinese-language content, it appears to force a specific language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document repeatedly frames the workflow as specifically for Chinese writing, including "增强中文语感" and "做中文措辞、文法、标点和段落润色," and later mandates Chinese punctuation and style conventions. Because the file gives prescriptive instructions without offering opt-in or explaining a region-specific requirement, it constitutes a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The line states '默认写现代简体中文' and instructs not to change the language unless the user explicitly asks. This sets a language default that can override user preference implicitly, and the file does not present an explicit language/locale choice or opt-in mechanism.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The default prompt says to use the skill to plan, write, or revise WeChat public account articles, but it does not define specific invocation triggers, boundaries, or exclusion conditions. In a manifest file, this broad natural-language activation guidance can lead to unintended matching for general writing requests related to articles.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.