Back to skill

Security audit

wechat-qa-checklist

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only WeChat article pre-publish checklist with no code, network behavior, persistence, or privileged actions.

Reasonable to install if you want a Chinese-language WeChat pre-publish checklist. Review the license terms before redistributing the text, because the package metadata says MIT while the document itself reserves rights over the checklist/theory text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
| 文档与理论文本 | 本 `SKILL.md`、`README.md`、其中「理论依据」段与一切理论表述 | **不在 MIT 覆盖范围内**:保留所有权利(All rights reserved) |

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L009 将“.py 文件”描述为受 MIT 覆盖,且 L010 将该文件作为一个可供 agent 使用的技能清单来声明工具范围;但 L096-L099、L114 又明确说本包无独立代码文件、整体为纯文档并保留所有权利。这不是单纯信息缺失,而是同一文件中的许可/包性质说明互相冲突,导致对技能实际构成与可用范围的理解发生偏差。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says the skill is used for questions like “推之前还要查什么” and “上次那个坑别再踩,” which are natural, everyday phrases in editorial work and do not clearly bound when this skill should activate instead of other writing or review skills. Although trigger_keywords are present, the natural-language invocation examples are broad and no exclusion conditions or negative examples are provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description lists trigger phrases such as “推送前检查”, “图片检查”, “标题检查”, and “编码问题”, which are generic terms that can easily arise in ordinary conversation about publishing or debugging. The trigger scope is not constrained by explicit activation rules or negative examples, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file begins with binding licensing/scope language primarily in Chinese, while the rest of the license text is in English. This creates a language-policy concern because the controlling notice is presented in a specific language without any explicit user opt-in or explanation that this locale choice is required.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

L051-L064 把该文件表述为可操作的技能清单,前置元数据也按 skill manifest 组织;但 L096-L097、L114 明确声称该包并无独立代码文件,只是纯文档/理论文本。这会让使用者对其到底是可执行技能还是仅文档资产产生误解,属于文档意图与实际资产描述之间的主动矛盾。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The skill description is entirely in Chinese and targets Chinese-language trigger phrases, but it does not state that use of Chinese is optional or that the skill is intentionally restricted to a Chinese-only regional workflow. This can be a natural-language locale policy issue when no user opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.