Back to skill

Security audit

微信智能聊天(MBTI版)

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it has high-impact chat automation and privacy risks that users should review before installing.

Install only if you are comfortable with a tool that reads active WeChat messages, sends chat-derived content to Qwen/Baidu-compatible services, and can automatically send replies. Use HTTPS-only endpoints, avoid entering secrets interactively until credential printing is fixed, run it only in low-risk chats or a test account, and prefer manual review before sending responses.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
wechatai.py:414
Finding

API Credentials Are Exposed Through Interactive Input and Console Logging

Content
View full analysis
&1 | tee debug.log ``` Under that documented workflow, the disclosed credentials can be persisted in a plaintext file. ### Attack Path 1. The user starts the Skill without setting `QWEN_API_KEY`. 2. The program prompts for Qwen and Baidu credentials. 3. The user enters the secrets, which are displayed because `input()` does not mask them. 4. The program prints all credentials in full at line 427. 5. Terminal output is retained ...[truncated 831 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
wechatai.py:303
Finding

Message-Derived Content Is Transmitted to Baidu Translate Over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
wechatai.py:240
Finding

Unrestricted Configurable Qwen Endpoint Can Receive Private Messages and Bearer Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Tainted flow: 'url' from os.environ.get (line 245, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The Qwen API destination is built from environment-controlled base URL and path, then called with an Authorization bearer token and user chat content. If those environment variables are maliciously modified, the script can exfiltrate private WeChat messages and API credentials to an attacker-controlled endpoint, making the environment taint materially security-relevant rather than a harmless configuration option.

Content

Scanner excerpt · wechatai.py (reported line 255)May include surrounding context.

python
"stream": stream
        }
        
        response = requests.post(
            url,
            headers=self.headers,
            json=payload,

Tainted flow: 'url' from os.environ.get (line 245, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The Baidu translation endpoint and path are also taken from environment variables and used for outbound requests carrying copied chat text plus API identifiers/signature material. Because the default endpoint is plain HTTP, and because a modified environment can redirect traffic elsewhere, intercepted or redirected requests could expose sensitive conversation data and service credentials.

Content

Scanner excerpt · wechatai.py (reported line 323)May include surrounding context.

python
# Send request
        url = self.endpoint + self.path
        r = requests.post(url, params=payload, headers=headers)
        result = r.json()
        
        # 检查是否有错误

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 59)May include surrounding context.

$env:QWEN_API_KEY="your-key"

...

或在 .env 文件中配置

text

## 🎯 使用方法

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose understates the actual behavior: the skill performs desktop/UI automation, clipboard reads and writes, window enumeration/control, continuous monitoring, and automatic message sending. This mismatch is dangerous because users may authorize what seems like translation/reply assistance without understanding that the tool can surveil active chats and inject messages into conversations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation says the skill monitors chat windows, copies message text, sends content to Qwen/Baidu APIs, and auto-sends replies, but it does not clearly warn that private chat data leaves the local machine and may be acted on automatically. In a messaging context this creates significant privacy and integrity risk, including accidental disclosure of sensitive conversations and unauthorized replies.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Clipboard-copied WeChat chat content is sent to external LLM and translation services without explicit warning, consent, or sensitivity checks. In this skill's context, that is especially dangerous because private conversations may contain personal, business, or authentication data, and the automation continuously monitors and reacts to chat content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog explicitly advertises automatic WeChat window monitoring and automatic response sending, but it provides no warning about privacy risks, unintended disclosure of chat content to external APIs, or the possibility of sending messages without meaningful user confirmation. In the context of a desktop tool that observes private chats and automates outbound messaging, this omission is security-relevant because users may unknowingly deploy behavior that can leak sensitive data and trigger unauthorized communications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly advertises automatic monitoring of WeChat messages and automatic sending of generated replies, but does not prominently warn about privacy exposure, unintended transmission, or the risk of acting on the wrong chat/window. In a tool that reads chat content and forwards it to external LLM/translation services, omission of these warnings increases the chance of accidental disclosure and unauthorized outbound messaging.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

md
| 变量名 | 必填 | 说明 | 示例 |
|--------|------|------|------|
| `QWEN_BASE_URL` | ✅ | Qwen 模型 API 基础地址 | `https://api.example.com/v1` |
| `QWEN_API_KEY` | ✅ | Qwen 模型 API 密钥 | `sk-xxx` |
| `QWEN_URL_PATH` | ✅ | Qwen API 接口路径 | `/chat/completions` |
| `BAIDU_APPID` | ✅ | 百度翻译 API APPID | `123456789` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 55)May include surrounding context.

md
| 变量名 | 必填 | 说明 | 示例 |
|--------|------|------|------|
| `QWEN_BASE_URL` | ✅ | Qwen 模型 API 基础地址 | `https://api.example.com/v1` |
| `QWEN_API_KEY` | ✅ | Qwen 模型 API 密钥 | `sk-xxx` |
| `QWEN_URL_PATH` | ✅ | Qwen API 接口路径 | `/chat/completions` |
| `BAIDU_APPID` | ✅ | 百度翻译 API APPID | `123456789` |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares environment-variable and network use but omits any explicit tool scope or permission boundaries. In a skill that sends chat content to external APIs and automates a desktop messaging client, missing scope declarations weakens user visibility and runtime containment, increasing the chance of overbroad access being granted implicitly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation language describes broad automatic monitoring of a WeChat window without clearly defining trigger conditions, scope limits, or excluded contexts. Ambiguous triggers are risky for messaging automation because the skill may process unintended conversations or continue operating longer than the user expects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description says the tool automatically translates content into Chinese, and later workflow text states English answers are automatically translated to Chinese. This is a locale/language constraint presented as default behavior without documenting user choice, opt-in, or justification for enforcing Chinese output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage instructions do not clearly emphasize that the skill can modify live conversations by injecting and sending messages on the user's behalf. That omission increases the likelihood of accidental misuse, especially if a user expects passive translation assistance rather than active message transmission.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest is a JSON file, so vague-trigger checks apply. The description "微信窗口自动监控、翻译和智能回复工具" describes broad capabilities but does not define specific activation phrases, contexts, or exclusion conditions, which could cause the skill to match loosely related requests involving WeChat, translation, or replies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest advertises automatic monitoring and reply behavior for a chat window but provides no visible warning about privacy, consent, or system-impact risks. In this context, the tool is likely to capture private conversations and forward them to external AI/translation endpoints, making undisclosed monitoring and third-party data disclosure a real security and privacy risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The manifest requires configuration for external Qwen and Baidu API endpoints, which indicates that captured chat content and generated prompts may be transmitted off-host. In this skill's context—automatic monitoring of a messaging window—external transmission is materially more dangerous because it can expose private conversations, credentials, or sensitive business data to third-party services, especially since the Baidu endpoint default is plain HTTP in the manifest.

Content

Scanner excerpt · package.json (reported line 37)May include surrounding context.

json
"QWEN_BASE_URL": {
      "description": "Qwen 模型 API 基础地址",
      "required": true,
      "example": "https://api.example.com/v1"
    },
    "QWEN_API_KEY": {
      "description": "Qwen 模型 API 密钥",

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code performs full GUI automation against WeChat: activating windows, scrolling, selecting text, copying from the clipboard, pasting generated text, and pressing Enter to send messages. Even if intended as convenience automation, this creates a powerful capability to read and act on private chats without per-message confirmation, increasing the risk of unintended disclosure, impersonation, or abuse if the script is misconfigured or modified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This code transmits user-derived content to an external API, which is notable because the source content comes from copied WeChat chats. External transmission is not automatically malicious, but in this skill context it is security-relevant since sensitive private messages are exported to a remote service as part of automated processing.

Content

Scanner excerpt · wechatai.py (reported line 255)May include surrounding context.

python
"stream": stream
        }
        
        response = requests.post(
            url,
            headers=self.headers,
            json=payload,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The helper function always translates output to Chinese with to_lang='zh', and the main flow invokes this behavior automatically when English is detected. This imposes a specific language/locale choice without user opt-in, which matches the language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

Natural-language policy checks apply to all file types. The package description is presented only in Chinese and does not indicate that the skill is intentionally limited to Chinese-speaking users or provide any language/locale choice, which can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency uses a lower-bound version specifier only (requests>=2.28.0), which makes builds non-reproducible and allows installation of unexpected future releases or vulnerable intermediary versions. In a tool that sends network requests and may process chat content, this increases supply-chain risk and makes it hard to verify whether known fixes are present.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0
pyautogui>=0.9.53
pyperclip>=1.8.2
pywin32>=305

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

requests has multiple known advisories, and because the manifest does not pin a version, it is impossible to determine whether deployments will receive a patched or affected release. In a skill that communicates with external translation/LLM services, using an unverifiable HTTP client version increases uncertainty around transport and credential-handling security.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

pyautogui>=0.9.53 is unpinned, so installations may resolve to different versions over time, undermining reproducibility and increasing supply-chain exposure. Because this package automates keyboard and mouse interaction, unexpected dependency changes could have amplified operational impact if a compromised or breaking release is installed.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.28.0
pyautogui>=0.9.53
pyperclip>=1.8.2
pywin32>=305

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

pyperclip>=1.8.2 is not pinned to a specific version, allowing uncontrolled version drift between environments. While the direct impact is generally limited, unpinned clipboard-related dependencies still create avoidable supply-chain and stability risk.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests>=2.28.0
pyautogui>=0.9.53
pyperclip>=1.8.2
pywin32>=305

Static analysis

No suspicious patterns detected.