Back to skill

Security audit

AI新闻多平台发布助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-news publishing workflow, but it can automatically post generated content to external social accounts without a clear enforced approval gate.

Install only if you are comfortable with a workflow that may post generated AI-news content to connected WeChat and Xiaohongshu accounts. Before using it, require draft-only defaults, explicit per-platform confirmation, pinned dependency versions, and review of sources, article text, image, and destination accounts before any scheduled or manual publication.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:68
Finding

Mutable and Unverifiable Third-Party Skill Dependencies

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 68-75; workflow.json, lines 9-74
Vulnerability Type: Supply-chain exposure through unpinned third-party Skills
Risk Level: Medium

Vulnerable Code Snippet

markdown
## Dependent Individual Skills

| Skill | Version | Purpose |
|-------|------|------|
| ai-news-daily | 1.0.3+ | Global AI news collection |
| agent-reach | latest | Multi-platform in-depth research |
| Public Account Assistant | latest | Long-form writing and formatting |
| nano-banana-pro | latest | AI cover image generation |
| wechat-mp-cn | latest | WeChat Official Account publishing |
| xiaohongshu-mcp | latest | Xiaohongshu content publishing |

The original dependency declarations use a minimum-version range for ai-news-daily and the mutable latest version for the other listed Skills. The workflow also identifies dependencies only by Skill name:

json
{
  "phase": 2,
  "name": "Deep Research",
  "skill": "agent-reach"
},
{
  "phase": 3,
  "name": "Article Writing",
  "skill": "Public Account Assistant"
},
{
  "phase": 4,
  "name": "Cover Generation",
  "skill": "nano-banana-pro"
},
{
  "phase": 5,
  "name": "WeChat Publishing",
  "skill": "wechat-mp-cn"
},
{
  "phase": 6,
  "name": "Xiaohongshu Publishing",
  "skill": "xiaohongshu-mcp"
}

Technical Analysis

The workflow delegates network research, content generation, image generation, and authenticated publishing to external Skills. Most dependencies are referenced using latest or without any version, artifact hash, signature, trusted publisher identifier, or immutable source location.

Consequently, the implementation executed at runtime may differ from the implementation that was originally reviewed. A compromised publisher account, malicious update, registry substitution, or similarly named component could alter a dependency after approval. This is ...[truncated 1717 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every external Skill to an exact, reviewed version rather than latest, a minimum-version range, or an unversioned name.
  2. Record immutable artifact hashes, signatures, and trusted publisher identities in the workflow or an associated lock file.
  3. Resolve dependencies exclusively through an allowlisted registry or repository with signature verification enabled.
  4. Review dependency updates before changing the lock file; do not update automatically in the production publishing workflow.
  5. Grant each Skill only the permissions required for its phase. Research and writing Skills should not receive publishing credentials.
  6. Isolate publishing connectors and provide short-lived, narrowly scoped tokens wherever the target platform supports them.
  7. Generate and retain a dependency inventory so the exact implementations used for each workflow execution can be audited.

T09 · Insecure Skill Coding Practices

Error
Location
workflow.json:19
Finding

Untrusted Remote Content Flows into Authenticated Publication Without an Enforced Approval Gate

Content
View full analysis

Vulnerability Details

File Location: workflow.json, lines 19-74
Vulnerability Type: Unsafe processing and automatic publication of untrusted content
Risk Level: High

Vulnerable Code Snippet

json
{
  "phase": 2,
  "name": "Deep Research",
  "skill": "agent-reach",
  "input": {
    "topic": "${daily_ai_news.hot_topic}"
  },
  "output": "research_report",
  "prompt": "Conduct in-depth research on the following AI topic: collect expert opinions, user feedback, and discussions from Twitter/X, Reddit, YouTube, Weibo, and other platforms, then produce a consolidated research report.",
  "parallel": false
},
{
  "phase": 3,
  "name": "Article Writing",
  "skill": "Public Account Assistant",
  "input": {
    "topic": "${daily_ai_news.hot_topic}",
    "research": "${research_report}",
    "style": "Business analysis style",
    "word_count": "3000-5000 words"
  },
  "output": "article_markdown",
  "prompt": "Based on the research report, write a professional long-form article using background, event description, in-depth analysis, original views, and recommendations."
},
{
  "phase": 4,
  "name": "Cover Generation",
  "skill": "nano-banana-pro",
  "input": {
    "prompt": "${article_markdown.title}",
    "size": "900x383",
    "style": "Professional modern technology style"
  },
  "output": "cover_image",
  "prompt": "Generate a professional, modern, premium cover image for this article title: ${article_markdown.title}."
},
{
  "phase": 5,
  "name": "WeChat Publishing",
  "skill": "wechat-mp-cn",
  "input": {
    "content": "${article_markdown}",
    "title": "${article_markdown.title}",
    "cover": "${cover_image}"
  },
  "output": "wechat_publish_result",
  "prompt": "Publish the article to the WeChat Official Account with its title, body, and cover image."
},
{
  "phase": 6,
  "name": "Xiaohongshu Publishing",
  "skill": "xiaohong
...[truncated 3240 chars]
Remediation
View remediation

Remediation Suggestions

  1. Insert a mandatory, non-bypassable human approval phase after article and cover generation and before either publishing phase.
  2. Default both publishing integrations to draft creation rather than immediate public publication.
  3. Treat all retrieved posts, comments, captions, transcripts, and linked pages as untrusted data. Place them in clearly delimited data fields and instruct processing Skills never to obey instructions found inside them.
  4. Normalize and filter retrieved material for prompt-injection patterns, hidden markup, encoded instructions, unexpected links, and irrelevant tool directives.
  5. Require independent verification of factual claims and citations before approval. Retain source URLs so reviewers can validate provenance.
  6. Apply output validation for prohibited content, unsupported allegations, personal data, unsafe links, platform policy violations, and unexpected instructions.
  7. Separate generation from publication credentials. Only the final publishing phase should have narrowly scoped platform authorization.
  8. Bind approval to a cryptographic hash of the exact title, body, summary, cover, and destination accounts so content cannot change after review.
  9. Record retrieved sources, generated output, reviewer identity, approval decision, and final publication results in tamper-evident audit logs.
  10. Require separate destination confirmation for WeChat and Xiaohongshu to prevent approval for one platform from implicitly authorizing publication to another.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description emphasizes content generation but does not clearly warn that the workflow automatically publishes to WeChat and Xiaohongshu. This lack of disclosure is dangerous because users may invoke the skill expecting draft creation only, while the workflow can perform irreversible external actions using linked publishing credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes fully automated multi-platform publishing to external services without clearly warning that generated content may be posted to user-linked accounts and third-party platforms. This can cause unintended publication, reputational harm, disclosure of sensitive content, or misuse of connected platform credentials if users do not understand the downstream effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scheduled execution section states that the workflow can run automatically every day, but it does not clearly warn that content generation and downstream publishing-related actions may occur on a timer. In this skill context, automation chained to publishing increases the risk of unattended posting, accidental dissemination of inaccurate or harmful content, and unexpected actions on user accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description advertises automatic publication to WeChat and Xiaohongshu but does not prominently warn that it will perform real posting actions against external accounts. Users may interpret this as a content-generation helper rather than an agent capable of taking irreversible or reputation-affecting actions on connected platforms.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow explicitly instructs publishing to external platforms in Phase 5 without any approval gate, dry-run mode, or warning about account-impacting consequences. In context, this is more dangerous because the same workflow also auto-generates the content, creating a path from broad trigger to unsupervised public posting of potentially inaccurate, policy-violating, or brand-damaging material.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are generic content-workflow requests such as '生成今日内容' and '发布公众号', which can cause this skill to activate in situations where the user did not clearly intend to run an automation that performs publishing. Because the skill chains together research, content generation, and external posting, broad triggers increase the risk of unintended account-impacting actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Natural-language strings in the manifest prescribe Chinese-platform publishing and a Chinese公众号 long-form article, but do not indicate that language or locale is optional or user-selected. Because SQP-3 applies to all file types, this is a policy concern when a skill enforces a specific language/locale without explicit opt-in or documented regional scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and overlap with ordinary content-generation or publishing requests, which increases the chance that this workflow is invoked unintentionally. Because the workflow culminates in posting to external platforms, accidental activation can cause unauthorized publication, reputational harm, or misuse of connected accounts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

All user-facing instructions and examples in this file are in Chinese, and the document does not state that the skill is China-specific or otherwise limited to Chinese-speaking users. Per the policy, forcing a specific language without opt-in or justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.