Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- This service exposes contact lookup and outbound WeChat messaging capabilities through unauthenticated HTTP endpoints, but the file provides no access control, purpose limitation, or abuse-prevention logic. In this context, the "unknown purpose" is not just a documentation issue: the code enables arbitrary message delivery to friends/groups, which can be repurposed for spam, impersonation, phishing, or unauthorized data exfiltration.
