T09 · Insecure Skill Coding Practices
- Location
wechat_sender.py:97- Finding
Contact index processing can send content to an unintended recipient
- Content
View full analysis
1: for _ in range(args.index - 1): pyautogui.press('down') time.sleep(0.2) pyautogui.press('enter') time.sleep(0.5) ``` The displayed comments and messages have been translated into English; the executable behavior is unchanged. ### Technical Analysis `search_contact()` presses Enter immediately after entering the contact name. This selects the first search result and normally changes the WeChat interface from the search-result list to a conversation. The program processes `--index` only after that transition. Consequently, the subsequent Down and Enter key presses no longer reliably operate on the search results. Depending on the current WeChat focus and layout, they may navigate within the conversation, activate another control, or send content unexpectedly. The program also does not inspect or verify the active conversation before typing and sending the message. Its correctness therefore depends entirely on UI timing, focus, and search-result ordering. ### Attack Path 1. A user or attacker supplies a contact name that matches multiple WeChat contacts. 2. The command is invoked with `--index` greater than one to select a later result. 3. `search_contact()` opens the first result before the index is processed. 4. The later Down and Enter events execute in the already-opened conversation or another unintended UI context. 5. The progr ...[truncated 631 chars]- Remediation
View remediation
