Back to skill

Security audit

WeChat Auto Reply

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned WeChat automation, but it can capture private chat UI and automatically send messages with broad local UI-control permissions and limited runtime safeguards.

Install only if you are comfortable giving this skill control over WeChat, clipboard, screen capture, and message sending. Prefer using it first with File Transfer Assistant or a test contact, disable or avoid auto-send where possible, review any Homebrew tap/formula before installation, and treat OCR screenshots/log output as potentially containing private chat data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
state_machine_final.py:72
Finding

Predictable Temporary Screenshot Files Expose Sensitive WeChat Content

Content
View full analysis
bool: X, Y, W, H = get_wechat_bounds() RX = X + int(W * 0.48) RY = Y + int(H * 0.80) RW = int(W * 0.48) RH = int(H * 0.17) img = '/tmp/wechat-input-check-final.png' screenshot_region(img, RX, RY, RW, RH) texts = vision_texts(img) joined = ' | '.join(texts) print('INPUT_OCR:', joined) return expected[:8] in joined or expected[:6] in joined ``` From `state_machine_test.py`: ```python img = "/tmp/wechat-search-state-machine.png" subprocess.run(["/usr/sbin/screencapture", f"-R{RX},{RY},{RW},{RH}", img], check=True) ``` ```python def confirm_input_has_message(expected: str) -> bool: X, Y, W, H = get_wechat_bounds() RX = X + int(W * 0.48) RY = Y + int(H * 0.80) RW = int(W * 0.48) RH = int(H * 0 ...[truncated 2554 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:40
Finding

Unpinned Packages and Third-Party Homebrew Tap Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
--hash=sha256: pyobjc-framework-Quartz== --hash=sha256: pyobjc-framework-Vision== --hash=sha256: pyobjc-framework-Cocoa== --hash=sha256: ``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script automatically sends a message after OCR-based confirmation without any user confirmation, preview, or pause. In the context of a desktop messaging automation skill with accessibility and screen-capture permissions, that can lead to unintended outbound messages, misdelivery to the wrong recipient, or abuse for covert communication.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill clearly describes shell-capable installation and execution steps but declares no tool scope or permissions boundary. In an automation skill that can send messages and read chat screenshots via OCR, missing explicit tool restrictions increases the chance of overbroad execution and unintended access to local data or UI automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states it will read current chat screenshots and generate replies, but the description does not prominently warn that private chat contents will be OCR-processed. This is dangerous because users may invoke it without understanding that sensitive conversations, names, and business information could be captured and processed locally or by downstream AI logic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill allows automatic sending when confidence is above 85%, but the user-facing description does not prominently emphasize that messages may be sent without final review. In a messaging context, automatic outbound communication can cause privacy leaks, impersonation, reputational harm, or accidental transmission to the wrong contact if OCR or targeting is incorrect.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

查看安装路径

bash
which wechat-auto-reply
ls -la ~/.openclaw/workspace/skills/wechat-auto-reply

环境准备

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
78% confidence
Finding

The function passes dynamically constructed AppleScript source into osascript, and multiple callers interpolate contact names or message text directly into that script. If those values contain quotes or AppleScript syntax, they can break out of the intended string context and alter GUI actions or execute unintended AppleScript commands on the local machine.

Content

Scanner excerpt · state_machine_final.py (reported line 12)May include surrounding context.

python
def osa(script: str) -> str:
    return subprocess.check_output(["osascript", "-e", script]).decode().strip()


def click(x: int, y: int, double: bool = False):

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · state_machine_final.py (reported line 17)May include surrounding context.

python
def click(x: int, y: int, double: bool = False):
    kind = "dc" if double else "c"
    subprocess.run(["/usr/local/bin/cliclick", f"{kind}:{x},{y}"], check=True)


def key_enter():

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · state_machine_test.py (reported line 18)May include surrounding context.

python
def click(x: int, y: int, double: bool = False):
    kind = "dc" if double else "c"
    subprocess.run(["/usr/local/bin/cliclick", f"{kind}:{x},{y}"], check=True)


def key_enter():

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · state_machine_final.py (reported line 79)May include surrounding context.

python
X, Y, W, H = get_wechat_bounds()
    RX, RY, RW, RH = X, Y + 60, 520, 520
    img = "/tmp/wechat-state-search.png"
    subprocess.run(["/usr/sbin/screencapture", f"-R{RX},{RY},{RW},{RH}", img], check=True)
    url = NSURL.fileURLWithPath_(img)
    req = VNRecognizeTextRequest.alloc().init()
    req.setRecognitionLanguages_(['zh-Hans', 'en-US'])

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · state_machine_test.py (reported line 81)May include surrounding context.

python
X, Y, W, H = get_wechat_bounds()
    RX, RY, RW, RH = X, Y + 60, 520, 520
    img = "/tmp/wechat-state-search.png"
    subprocess.run(["/usr/sbin/screencapture", f"-R{RX},{RY},{RW},{RH}", img], check=True)
    url = NSURL.fileURLWithPath_(img)
    req = VNRecognizeTextRequest.alloc().init()
    req.setRecognitionLanguages_(['zh-Hans', 'en-US'])

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · state_machine_test.py (reported line 128)May include surrounding context.

python
X, Y, W, H = get_wechat_bounds()
    RX, RY, RW, RH = X, Y + 60, 520, 520
    img = "/tmp/wechat-state-search.png"
    subprocess.run(["/usr/sbin/screencapture", f"-R{RX},{RY},{RW},{RH}", img], check=True)
    url = NSURL.fileURLWithPath_(img)
    req = VNRecognizeTextRequest.alloc().init()
    req.setRecognitionLanguages_(['zh-Hans', 'en-US'])

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill captures portions of the WeChat window and performs OCR without any runtime disclosure, confirmation, or data-handling controls. That can expose message contents, contact names, and other sensitive on-screen information, especially because screenshots are written to /tmp where remnants may persist.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · state_machine_final.py (reported line 122)May include surrounding context.

python
def screenshot_region(path: str, rx: int, ry: int, rw: int, rh: int):
    subprocess.run(["/usr/sbin/screencapture", f"-R{rx},{ry},{rw},{rh}", path], check=True)


def confirm_clean_chat_state():

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script automatically sends a message once its state checks pass, without a final user confirmation step. In a messaging context, unintended dispatch can cause privacy leaks, reputational damage, or accidental delivery to the wrong contact if OCR or UI state detection is wrong.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script hard-codes both the contact and the message, then sends automatically, which bypasses the manifest-described user-invoked interface and removes user control over message destination and content. In a messaging skill, this increases the chance of unintended or covert message transmission, especially because the code is ready to operate once permissions are granted.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · state_machine_test.py (reported line 13)May include surrounding context.

python
def osa(script: str) -> str:
    return subprocess.check_output(["osascript", "-e", script]).decode().strip()


def click(x: int, y: int, double: bool = False):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill captures the WeChat UI without an explicit disclosure or warning at the point of use. Since WeChat windows may display private contacts, groups, and message fragments, silent capture meaningfully increases privacy risk even if the capture is limited to supporting automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Temporary screenshots of the message input area are written to /tmp, which may expose sensitive message content to other local processes, backups, or later forensic recovery. The risk is higher here because the capture targets draft text the user may not realize is being stored on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

This shell script invokes osascript to perform direct message sending and OCR-based auto-reply actions, which can affect user communications and potentially send messages automatically. Although the usage examples mention the behavior, there is no explicit confirmation prompt or clear safety warning immediately before execution about automatic message transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example sets recognition languages to only "zh-Hans" and "en-US", which imposes a language/locale constraint in the skill description without presenting it as a user choice. This may violate language/locale policy expectations unless the restriction is explicitly justified or made configurable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The contact name and outbound message are fixed in Chinese, and the OCR flow is configured around Chinese and US English recognition, which reflects a locale-specific behavior. The file does not provide user opt-in, language selection, or documentation that this skill is intentionally limited to a Chinese WeChat workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code screenshots part of the WeChat window and runs OCR over it, a capability broader than simple message sending and not clearly disclosed in the skill description. Because chat lists and UI regions may contain sensitive names or message snippets, this expands the skill into local data collection and privacy exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

All user-facing usage and example text is presented only in Chinese, with no indication that another language can be used or selected. This may violate a language/locale policy requiring user choice or opt-in rather than enforcing a single language by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.