Back to skill

Security audit

Wechat Sender

Security checks for vulnerabilities and agentic risk

Overview

This WeChat automation skill is purpose-aligned but should be reviewed because it can send messages or local file paths immediately to the wrong chat without confirming the recipient.

Install only if you are comfortable with keyboard-driven WeChat automation. Use `--no-send` by default, manually verify the selected chat before pressing Enter, avoid sensitive messages or file paths, and do not rely on the `--file` option to attach a file because it types the path as chat text.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
wechat_sender.py:97
Finding

Contact index processing can send content to an unintended recipient

Content
View full analysis
1: for _ in range(args.index - 1): pyautogui.press('down') time.sleep(0.2) pyautogui.press('enter') time.sleep(0.5) ``` The displayed comments and messages have been translated into English; the executable behavior is unchanged. ### Technical Analysis `search_contact()` presses Enter immediately after entering the contact name. This selects the first search result and normally changes the WeChat interface from the search-result list to a conversation. The program processes `--index` only after that transition. Consequently, the subsequent Down and Enter key presses no longer reliably operate on the search results. Depending on the current WeChat focus and layout, they may navigate within the conversation, activate another control, or send content unexpectedly. The program also does not inspect or verify the active conversation before typing and sending the message. Its correctness therefore depends entirely on UI timing, focus, and search-result ordering. ### Attack Path 1. A user or attacker supplies a contact name that matches multiple WeChat contacts. 2. The command is invoked with `--index` greater than one to select a later result. 3. `search_contact()` opens the first result before the index is processed. 4. The later Down and Enter events execute in the already-opened conversation or another unintended UI context. 5. The progr ...[truncated 631 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
wechat_sender.py:108
Finding

Sensitive message contents and local file paths are printed in plaintext

Content
View full analysis
50 else f"Sending message: {message}") ``` ```python print(f"Sending file: {file_path}") ``` The displayed message labels have been translated into English; the data-handling behavior is unchanged. ### Technical Analysis The application prints either the complete message or its first 50 characters to standard output. It also prints the complete local file path supplied through `--file`. Standard output may be retained by agent execution logs, terminal capture, shell wrappers, CI systems, monitoring software, or remote administration tooling. The truncation applied to long messages does not provide meaningful protection because the first 50 characters can contain credentials, tokens, personal information, or the most sensitive part of a message. Full paths can reveal usernames, project names, customer names, directory layouts, and sensitive filenames. ### Attack Path 1. A user invokes the skill with a confidential message or a sensitive local file path. 2. The script emits the message content or path to standard output. 3. The output is captured by the surrounding agent framework, terminal logger, monitoring system, or another process with access to execution logs. 4. A user with log access retrieves the sensitive content without needing access to the WeChat conversation itself. ### Impact Assessment This issue does not elevate privileges. Disclosure is limited to data supplied to the process and to parties capable of reading its output or retained logs. Potentially exposed information includes private message text, personal data, authentication material embedded in messages, local usernames, directory structures, project identifiers, and sensitive filenames. ...[truncated 3 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
wechat_sender.py:116
Finding

The documented file-transfer operation sends a local path as chat text instead of attaching the file

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:77
Finding

Third-party dependency installation is not version- or integrity-pinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function sends file-related content to a chat by automated GUI input and pressing Enter, which can disclose local file information or transmit unintended content. The script logs the action, but it does not require a final user confirmation before performing the send operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description presents the tool as a convenient WeChat sender but does not prominently warn that it uses keyboard simulation and may misfire if focus changes, the wrong window is active, or contact selection is ambiguous. In a GUI automation context, insufficient warning increases the chance that users invoke the tool without understanding it can send messages or files to unintended recipients.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad everyday expressions such as '发微信' and '发消息给 XXX', which can cause the skill to activate unintentionally during normal conversation. Because this skill performs GUI automation to send messages/files in WeChat, a false trigger can lead to unintended outbound communication or file transfer, making the context significantly more dangerous than a read-only or informational skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script sends chat messages immediately after searching for a contact, without any explicit confirmation that the correct window and recipient are selected. Because it relies on GUI focus and keystroke injection, a mistargeted window, wrong search result, or manipulated desktop state could cause unintended messages to be sent to the wrong recipient.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function is documented and logged as '发送文件' (send file), but the implementation does not attach or upload any file. Instead, it writes the local file path into the chat input and presses Enter, which sends text rather than the file itself.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The comment says the tool directly drags a file into the WeChat window, but the following line only calls pyautogui.write(file_path). This is an active contradiction between the code comments and the real behavior, not merely missing detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.