Back to skill

Security audit

一键生成PPT截图和缩略图工具发布到微信去的工具,MAC版本

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it asks users to expose WeChat credentials and automatically uploads local presentation content to WeChat without a clear confirmation step.

Review before installing. Do not paste real WeChat secrets into chat or commit them in config.json; use a secret manager or environment variables and rotate any secret already shared. Only run this on PPT files you are comfortable uploading to WeChat, and add a manual review/confirmation step before network upload or draft creation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
config.json:12
Finding

Plaintext WeChat Secret Storage and Exposure in Request URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README instructs users to provide WeChat app credentials but gives no warning about secret handling, storage, logging, or safer input channels. This creates a real risk of credential exposure in chat history, agent logs, transcripts, or downstream tooling, especially because the documentation normalizes sharing secrets directly with the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown describes usage only through a free-form example prompt and does not define specific trigger phrases, boundaries, or negative examples. This can make activation ambiguous and increase the chance of unintended invocation from ordinary requests about generating images or publishing content.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The example prompt explicitly tells the user to paste wechat_appid and wechat_appsecret into natural-language input. That is dangerous because conversational interfaces are commonly logged, retained, or exposed to operators and other components, turning the documentation into an inducement for secret disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that users need to provide their WeChat credentials, establishing an unnecessary sensitive data collection pattern without guidance on secure handling. In the context of an agent skill, this increases the chance that secrets are passed through unsafe channels or persisted in configs, prompts, or logs.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · ppt2wechat.py (reported line 40)May include surrounding context.

python
]

    print("正在转换 PPT → PDF")
    subprocess.run(cmd, check=True)

    pdf_path = output_dir / (ppt_path.stem + ".pdf")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · ppt2wechat.py (reported line 66)May include surrounding context.

python
]

    print("正在转换 PPT → PDF")
    subprocess.run(cmd, check=True)

    pdf_path = output_dir / (ppt_path.stem + ".pdf")

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script is capable of automatically uploading local images and creating WeChat drafts, which causes external transmission of local content and use of stored platform credentials. In an agent-skill context with no documented consent, approval, or scope controls, this expands the blast radius because local files can be published to a third-party service without an explicit user checkpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code sends app credentials and local file contents to WeChat APIs without any user-facing disclosure, consent flow, or runtime warning. In an automation/agent setting, silent exfiltration of presentation-derived images and credential use is risky because users may not realize external transmission is occurring.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This API call sends application credentials to obtain an access token from WeChat. Although normal for the feature, it is security-sensitive in a skill context because it initiates third-party access using stored secrets without any explicit user approval or disclosure in the workflow.

Content

Scanner excerpt · ppt2wechat.py (reported line 134)May include surrounding context.

python
# =============================
def get_access_token(appid, secret):

    url = f'https://api.weixin.qq.com/cgi-bin/token?grant_type=client_credential&appid={appid}&secret={secret}'

    r = requests.get(url).json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This endpoint uploads a local image file externally as permanent WeChat material, which is a direct data-transfer action. If the working directory contains sensitive presentation content, this can expose local data to a third party, especially dangerous when performed automatically inside an agent workflow.

Content

Scanner excerpt · ppt2wechat.py (reported line 143)May include surrounding context.

python
def upload_permanent_image(access_token, file_path):

    url = f'https://api.weixin.qq.com/cgi-bin/material/add_material?access_token={access_token}&type=image'

    with open(file_path, 'rb') as f:

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This API call uploads local images to WeChat to obtain externally hosted URLs, again transmitting presentation-derived content off the machine. The code performs this automatically for all pages after the cover, making unintended disclosure more likely if inputs are confidential or if the skill is triggered unexpectedly.

Content

Scanner excerpt · ppt2wechat.py (reported line 154)May include surrounding context.

python
def upload_image_get_url(access_token, file_path):

    url = f'https://api.weixin.qq.com/cgi-bin/media/uploadimg?access_token={access_token}'

    with open(file_path, 'rb') as f:

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This request transmits article content and metadata to an external WeChat endpoint, potentially publishing derived local data to a third-party platform. In an agent skill, undisclosed outbound transmission is security-relevant because it can move sensitive presentation content off-host without a separate approval boundary.

Content

Scanner excerpt · ppt2wechat.py (reported line 202)May include surrounding context.

python
data = {"articles": [article]}

    r = requests.post(
        "https://api.weixin.qq.com/cgi-bin/draft/add",
        params={"access_token": access_token},
        data=json.dumps(data, ensure_ascii=False).encode("utf-8"),

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This is the same draft-creation transmission path as the prior finding, identified at the concrete URL line. It sends generated article content to WeChat, which is security-relevant because it externalizes local content in an automated manner without user-facing safeguards.

Content

Scanner excerpt · ppt2wechat.py (reported line 203)May include surrounding context.

python
data = {"articles": [article]}

    r = requests.post(
        "https://api.weixin.qq.com/cgi-bin/draft/add",
        params={"access_token": access_token},
        data=json.dumps(data, ensure_ascii=False).encode("utf-8"),
        headers={"Content-Type": "application/json"}

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This is a manifest-style JSON file, but it provides only operational configuration values and no explicit trigger phrases, activation boundaries, or exclusion conditions. For manifest files, missing specificity around how and when the skill should activate can lead to ambiguous or unintended invocation behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The filename value includes Chinese text, which suggests the skill may be oriented toward a specific language or locale, but this file does not indicate any user opt-in or documented locale constraint. Under the policy rule, forcing or assuming a language without clear user choice can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

compress_image modifies files in place by reopening and saving them back to the same path, which is a file write that changes generated assets irreversibly. The code does not provide a warning, confirmation, or comment explaining that image quality will be reduced and the original file contents replaced.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The section header '发布微信草稿' indicates publishing a WeChat draft, but the implementation calls the draft creation endpoint '/cgi-bin/draft/add' and never invokes a publish action. This is an active documentation-to-code mismatch about the operation's actual effect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.