Back to skill

Security audit

Wechat Qwen Reply

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent WeChat OCR purpose, but it uploads private chat screenshots and runs unbundled PowerShell capture scripts from a fixed local workspace, so it needs careful review before installation.

Install only if you are comfortable with WeChat screenshots being sent to DashScope for processing, sensitive chat text and images being saved in the local workspace, and unreviewed PowerShell/AHK scripts outside the package controlling capture or sending behavior. Verify the external scripts yourself and avoid using it on confidential personal, business, payment, or account conversations.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/qwen_vl_read.py:15
Finding

Execution of Mutable External PowerShell Scripts with Execution-Policy Bypass

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/qwen_vl_read.py:62
Finding

Private Chat Screenshots Are Persisted and Uploaded Without Explicit Privacy Disclosure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Screenshot-derived chat content is highly sensitive, and transmitting it off-host without any user-facing warning materially increases privacy and compliance risk. In the context of a WeChat reader/auto-reply skill, this is especially dangerous because users may expect local automation, not cloud upload of private conversations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and relies on capabilities equivalent to file read/write, network access, and shell execution, but it does not declare any explicit tool scope or permissions. That omission weakens user awareness and review controls, especially for a skill that reads local files, calls a remote API, captures the screen, and can automate message sending.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill exposes a concrete local path to an API key file, revealing secret storage location and encouraging direct file-based credential handling without any warning about sensitivity. In practice, this increases the chance of accidental disclosure, unauthorized reads by related tooling, or unsafe reuse of the path in logs, prompts, or scripts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill includes automated WeChat message sending via AHK, but the description does not warn users about the risks of sending messages automatically on their behalf. In this context, the capability is especially sensitive because the same skill also reads chat content and could be used to relay, spoof, or accidentally send unintended messages to contacts or groups.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/qwen_vl_read.py (reported line 18)May include surrounding context.

python
def run_ps(args):
    cmd = ["powershell", "-ExecutionPolicy", "Bypass", "-File"] + args
    res = subprocess.run(cmd, capture_output=True, text=True)
    if res.returncode != 0:
        raise RuntimeError(res.stderr.strip() or res.stdout.strip())
    return res.stdout.strip()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script reads an API key from a dedicated secrets path, which is access to sensitive credentials under the rule criteria. There is no comment or user-facing disclosure explaining credential usage, scope, or that the key will be used to authenticate outbound requests to a third-party service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script captures WeChat chat screenshots and sends the image contents to a third-party cloud API for OCR/vision processing. This is sensitive message exfiltration to an external service, and the code provides no consent flow, minimization, or disclosure despite handling private chat content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
69% confidence
Finding

The stated purpose is reading WeChat chats and auto-replying, but this script additionally accesses a fixed local secrets path to obtain cloud credentials. While related to the remote vision call, credential-file access is a separate capability not justified by the manifest text as written.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.