weixin-mcp

Security checks across malware telemetry and agentic risk

Overview

This WeChat skill is transparent about its purpose, but it should be reviewed because it can send/read messages and run a changeable external CLI with broad activation triggers.

Install only if you trust the `weixin-mcp` npm/GitHub package and are comfortable granting it access to a WeChat bot account. Prefer an exact reviewed package version, use a dedicated bot account, keep webhooks local or trusted, confirm recipients and attachments before sending, protect token files, and stop the daemon when real-time receiving is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list contains very broad single-word activators such as "weixin", "wechat", and "微信", which are likely to appear in ordinary user conversation without an explicit intent to invoke this skill. That can cause accidental activation of a message-sending or inbox-checking integration, creating unintended access to messaging actions or disclosure of message data in contexts where the user only mentioned the service generically.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal