Back to skill

Security audit

wechat-viral-topic

Security checks for vulnerabilities and agentic risk

Overview

This is a document-only viral content planning skill with some legal and language-scope caveats, but no hidden code execution, persistence, credential access, or destructive behavior was found.

Install only if you want a Chinese-first viral topic and headline planning framework. Review the licensing terms before redistributing or modifying the written materials, and apply your own editorial judgment so emotional hooks do not become misleading, exploitative, or noncompliant engagement bait.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
| 文档与理论文本 | 本 `SKILL.md`、`README.md`、其中「理论依据」段与一切理论表述 | **不在 MIT 覆盖范围内**:保留所有权利(All rights reserved) |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Presenting the operative scope restrictions only in Chinese can prevent some users from understanding that the MIT grant is being narrowed to .py files and excludes SKILL.md, README.md, and theoretical text. In a cross-border distribution context, this can cause accidental noncompliance, improper reuse, or disputes over what content is actually licensed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest lists generic trigger keywords "wechat", "viral", and "topic" without clarifying required combinations, context, or exclusion conditions. These terms are broad enough to overlap with ordinary content-planning discussion, which could cause unintended invocation of the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The line instructs publishers to copy the block "整体复制、未删改", while the surrounding required attribution block is presented in Chinese-dominant form despite the skill declaring multiple supported languages. This creates a natural-language locale constraint without explicit user opt-in or an offered language choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest advertises very broad trigger phrases such as '选题', '热点', and '这周写什么', which are common expressions that can appear in many unrelated conversations. This raises the chance of unintended skill invocation, causing the agent to activate outside the user's intended context and potentially override or interfere with more appropriate skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file appears to require Chinese-language comprehension throughout, including headings, instructions, and examples, but it does not indicate that the user can choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The title and document content are entirely in Chinese and present the principles as mandatory guidance, but there is no indication that the skill is intentionally region-specific or that users may choose another language. Per the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section explicitly teaches how to trigger high-arousal emotions such as anger, anxiety, and superiority to maximize sharing, but provides only minimal caution and no meaningful safeguards against manipulative, misleading, or harmful persuasive use. In the context of a viral-topic ideation skill for public content creators, this can facilitate engagement bait, outrage farming, and emotionally coercive messaging at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The self-check templates are written as mandatory output text in Chinese, and the document does not indicate that users may choose another language or locale. This can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file is entirely prescriptive content in Chinese for generating titles, with no indication that users may choose another language or locale. Under the policy rule for language/locale, a skill that effectively constrains output to a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction "模型必须严格按本模板输出" combined with the entire template being written in Chinese requires the model to respond in Chinese regardless of user preference. This is a natural-language locale policy issue because the file does not offer any language choice or explain a justified region-specific restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The license text introduces a broad cross-reference to SKILL.md for a 'complete layered statement' while simultaneously limiting MIT coverage to only certain files. This creates ambiguity about which terms govern non-code content and can mislead downstream users about redistribution rights, increasing legal and supply-chain risk even though it is not a code-execution issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The SVG's title and description are written entirely in Chinese, which embeds a fixed language choice in user-facing metadata. For a file subject to policy checks across all file types, this can be a locale/language policy issue when no opt-in, alternative language, or justification for the language restriction is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

All instructional content and examples are presented only in Chinese, with no indication that users may choose another language or that the scope is intentionally limited to Chinese-language social-media writing. Under the stated policy, a skill should not implicitly force a specific language unless the locale constraint is documented and justified or the user can opt in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains natural-language instructions and examples exclusively in Chinese, which can amount to a language-policy issue if users are not given an opt-in or alternative locale. The file does not indicate that the skill is intentionally limited to Chinese-speaking users or provide any multilingual option.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.