T07 · Tool Hijacking and Spoofing
- Location
scripts/qwen_vl_read.py:15- Finding
Execution of Mutable External PowerShell Scripts with Execution-Policy Bypass
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent WeChat OCR purpose, but it uploads private chat screenshots and runs unbundled PowerShell capture scripts from a fixed local workspace, so it needs careful review before installation.
Install only if you are comfortable with WeChat screenshots being sent to DashScope for processing, sensitive chat text and images being saved in the local workspace, and unreviewed PowerShell/AHK scripts outside the package controlling capture or sending behavior. Verify the external scripts yourself and avoid using it on confidential personal, business, payment, or account conversations.
scripts/qwen_vl_read.py:15Execution of Mutable External PowerShell Scripts with Execution-Policy Bypass
scripts/qwen_vl_read.py:62Private Chat Screenshots Are Persisted and Uploaded Without Explicit Privacy Disclosure
Screenshot-derived chat content is highly sensitive, and transmitting it off-host without any user-facing warning materially increases privacy and compliance risk. In the context of a WeChat reader/auto-reply skill, this is especially dangerous because users may expect local automation, not cloud upload of private conversations.
The skill advertises and relies on capabilities equivalent to file read/write, network access, and shell execution, but it does not declare any explicit tool scope or permissions. That omission weakens user awareness and review controls, especially for a skill that reads local files, calls a remote API, captures the screen, and can automate message sending.
The skill exposes a concrete local path to an API key file, revealing secret storage location and encouraging direct file-based credential handling without any warning about sensitivity. In practice, this increases the chance of accidental disclosure, unauthorized reads by related tooling, or unsafe reuse of the path in logs, prompts, or scripts.
The skill includes automated WeChat message sending via AHK, but the description does not warn users about the risks of sending messages automatically on their behalf. In this context, the capability is especially sensitive because the same skill also reads chat content and could be used to relay, spoof, or accidentally send unintended messages to contacts or groups.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_ps(args):
cmd = ["powershell", "-ExecutionPolicy", "Bypass", "-File"] + args
res = subprocess.run(cmd, capture_output=True, text=True)
if res.returncode != 0:
raise RuntimeError(res.stderr.strip() or res.stdout.strip())
return res.stdout.strip()
The script reads an API key from a dedicated secrets path, which is access to sensitive credentials under the rule criteria. There is no comment or user-facing disclosure explaining credential usage, scope, or that the key will be used to authenticate outbound requests to a third-party service.
The script captures WeChat chat screenshots and sends the image contents to a third-party cloud API for OCR/vision processing. This is sensitive message exfiltration to an external service, and the code provides no consent flow, minimization, or disclosure despite handling private chat content.
The stated purpose is reading WeChat chats and auto-replying, but this script additionally accesses a fixed local secrets path to obtain cloud credentials. While related to the remote vision call, credential-file access is a separate capability not justified by the manifest text as written.
No suspicious patterns detected.