All skills
jimliu avatar

/baoyu-post-to-wechat

@441ca30 official
by Jim Liu 宝玉jimliu/baoyu-skills26k stars
2,896

Posts content to WeChat Official Account (微信公众号) via API or Chrome CDP. Supports article posting (文章) with HTML, markdown, or plain text input, and image-text posting (贴图, formerly 图文) with multiple images. Markdown article workflows default to converting ordinary external links into bottom citations for WeChat-friendly output. Use when user mentions "发布公众号", "post to wechat", "微信公众号", or "贴图/图文/文章".

Use this Skill: https://skilld.dev/gh/jimliu/baoyu-skills/baoyu-post-to-wechat

This session only. Nothing lands on disk.

referencesmulti-account.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Multi-Account Support

Details for managing multiple WeChat Official Accounts through one EXTEND.md. SKILL.md only covers single-account flow and the selection prompt — read this file when the user has an accounts: block, asks to publish to a specific account, or needs per-account credentials.

Compatibility

Condition Mode Behavior
No accounts block Single-account Original behavior, no changes
accounts with 1 entry Single-account Auto-select, no prompt
accounts with 2+ entries Multi-account Prompt to select before publishing
accounts with default: true Multi-account Pre-select default; user can switch

EXTEND.md Example

default_theme: default
default_color: blue

accounts:
  - name: 宝玉的技术分享
    alias: baoyu
    default: true
    default_publish_method: api
    default_author: 宝玉
    need_open_comment: 1
    only_fans_can_comment: 0
    app_id: your_wechat_app_id
    app_secret: your_wechat_app_secret
  - name: AI工具集
    alias: ai-tools
    default_publish_method: browser
    default_author: AI工具集
    need_open_comment: 1
    only_fans_can_comment: 0

Per-Account vs Global Keys

Per-account (also accepted globally as fallback): default_publish_method, default_author, need_open_comment, only_fans_can_comment, app_id, app_secret, chrome_profile_path, remote_publish_host, remote_publish_user, remote_publish_port, remote_publish_identity_file, remote_publish_known_hosts_file, remote_publish_strict_host_key_checking, remote_publish_connect_timeout, remote_publish_proxy_jump.

Global-only (always shared): default_theme, default_color.

Account Selection (Step 0.5)

Insert between Step 0 (Load EXTEND.md) and Step 1 (Determine input type):

if no accounts block:
    → single-account mode (original behavior)
elif accounts.length == 1:
    → auto-select the only account
elif --account <alias> CLI arg:
    → select matching account
elif one account has default: true:
    → pre-select, display: "Using account: <name> (--account to switch)"
else:
    → prompt user to choose from the list

Credential Resolution (API Method)

For the selected account with alias {alias}, try in this order (first hit wins):

  1. app_id / app_secret inline in the EXTEND.md account block
  2. Env vars WECHAT_{ALIAS}_APP_ID / WECHAT_{ALIAS}_APP_SECRET (alias uppercased, hyphens → underscores)
  3. .baoyu-skills/.env with the prefixed key WECHAT_{ALIAS}_APP_ID
  4. ~/.baoyu-skills/.env with the prefixed key
  5. Fallback to unprefixed WECHAT_APP_ID / WECHAT_APP_SECRET

.env Multi-Account Example

# Account: baoyu
WECHAT_BAOYU_APP_ID=your_wechat_app_id
WECHAT_BAOYU_APP_SECRET=your_wechat_app_secret

# Account: ai-tools
WECHAT_AI_TOOLS_APP_ID=your_ai_tools_wechat_app_id
WECHAT_AI_TOOLS_APP_SECRET=your_ai_tools_wechat_app_secret

Chrome Profile (Browser Method)

Each account uses an isolated Chrome profile so logins don't collide.

Source Path
Account chrome_profile_path in EXTEND.md Use as-is
Auto-generated from alias {shared_profile_parent}/wechat-{alias}/
Single-account fallback Shared default profile

CLI --account Flag

All publishing scripts accept --account <alias>:

${BUN_X} {baseDir}/scripts/wechat-api.ts <file> --theme default --account ai-tools
${BUN_X} {baseDir}/scripts/wechat-article.ts --markdown <file> --theme default --account baoyu
${BUN_X} {baseDir}/scripts/wechat-browser.ts --markdown <file> --images ./photos/ --account baoyu

Remote API Publishing

wechat-api.ts supports a remote-api mode that tunnels WeChat API calls through an SSH SOCKS5 dynamic port forward to a server whose IP is on WeChat's allowlist. Markdown rendering, image processing, draft assembly, and HTML rewriting still happen locally; only outbound HTTPS calls to api.weixin.qq.com traverse the tunnel. No files are written to the remote host and AppSecret never leaves the local process. The remote host needs only sshd and outbound network access.

Per-Account Configuration

default_theme: default
default_color: blue
default_publish_method: browser   # browser remains the default

accounts:
  - name: 宝玉的技术分享
    alias: baoyu
    default: true
    default_publish_method: api
    default_author: 宝玉
    app_id: your_wechat_app_id
    app_secret: your_wechat_app_secret
  - name: AI工具集
    alias: ai-tools
    default_publish_method: remote-api
    default_author: AI工具集
    app_id: your_ai_tools_app_id
    app_secret: your_ai_tools_app_secret
    remote_publish_host: ai-tools-server.example.com
    remote_publish_user: deploy
    remote_publish_port: 22
    remote_publish_identity_file: /home/me/.ssh/id_ed25519
    remote_publish_known_hosts_file: /home/me/.ssh/known_hosts
    remote_publish_strict_host_key_checking: accept-new

Account-level remote_publish_* values override top-level globals. CLI --remote-* flags override both.

CLI Usage

# Use the account's default_publish_method (remote-api here):
${BUN_X} {baseDir}/scripts/wechat-api.ts <file> --theme default --account ai-tools

# Force remote mode regardless of default_publish_method:
${BUN_X} {baseDir}/scripts/wechat-api.ts <file> --theme default --account baoyu --remote --remote-host other-server.example.com

Security Notes

  • Authentication is SSH key only. Passwords and ssh-askpass are not used.
  • Only the typed remote_publish_* keys are read; raw ssh / scp options are intentionally not supported.
  • The tunnel forwards raw TCP; TLS verification for api.weixin.qq.com is still performed end-to-end by the local process.

Source: SKILL.md on GitHub

2 warnings16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides workflows for automated content publishing to WeChat Official Accounts via API methods or Chrome CDP. The technical capabilities (spawning processes, controlling Chrome, clipboard interactions, managing local configuration files and environment secrets) align with its designated function. There are no malicious elements, exfiltration patterns, or obfuscation flags identified during analysis.

  • Socket16d

    3 alerts: gptSecurity, gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    77/126 files flagged

  • ZeroLeaks5mo

    1 finding · Score: 86/100

Signed by skilld at 441ca30. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 months ago
version
1.118.2
Other metadata
metadata
{
  "openclaw": {
    "homepage": "https://github.com/JimLiu/baoyu-skills#baoyu-post-to-wechat",
    "requires": {
      "anyBins": [
        "bun",
        "npx"
      ]
    }
  }
}
  • API
  • wechat
  • markdown
  • html
  • browser
  • automation
  • chrome-cdp
  • image-upload
  • cms
  • china

README badge

README badge for jimliu/baoyu-skills/baoyu-post-to-wechat

Publishes articles and image-text posts to WeChat Official Accounts via API or Chrome automation, with support for HTML, markdown, or plain text input. Converts markdown links to bottom citations by default and handles cover images, themes, colors, and multi-account management through local configuration.

Generated from the current SKILL.md.

Does this skill work with plain text, markdown, and HTML input?
Yes. Plain text is saved to a timestamped markdown file, markdown files are processed with optional citation conversion, and HTML files are posted as-is. The publishing method (API or browser) determines how images are handled internally.
What are the differences between API, browser, and remote-api publishing methods?
API is fastest and requires local IP allowlisting or remote-api tunneling; browser is slower but needs only a logged-in Chrome session; remote-api uses SSH to tunnel API calls through an allowlisted server IP without writing files or exposing credentials remotely.
Can I manage multiple WeChat Official Accounts with this skill?
Yes. Define an `accounts:` block in EXTEND.md with multiple entries. The skill prompts for account selection or auto-selects based on `default: true` or the `--account` CLI flag.
What are the cover image requirements?
For API publishing with article type `news`, a cover image is required. The skill looks for it via CLI `--cover`, frontmatter fields (`coverImage`, `featureImage`, `cover`, `image`), a file at `imgs/cover.png`, or the first inline image in the content.
How do I set up API credentials for the first time?
If credentials are missing when API or remote-api is selected, the skill runs a guided setup that writes them to `.baoyu-skills/.env`. You can also configure them manually before first use per `references/api-setup.md`.

Generated from the current SKILL.md. These answers refresh after source changes.