Back to skill

Security audit

企业微信 AI Bot 对接

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for configuring a WeCom/OpenClaw bot, but it handles bot credentials and broad access defaults in ways users should review carefully before installing.

Install only if you are comfortable reviewing the package source and plugin version yourself. Prefer pinned package and plugin versions, avoid passing the Secret on the command line, enter credentials only in a private terminal, restrict the OpenClaw config file to owner-only permissions, and change dmPolicy to pairing or allowlist for any shared or production bot.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T08 · Insecure Dependencies

Error
Location
SKILL.md:24
Finding

Unpinned Third-Party Packages Can Introduce Mutable Supply-Chain Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup_wecom.py:76
Finding

Bot Secret Can Be Exposed Through Command-Line Arguments

Content
View full analysis
`. 2. The complete command may be stored in shell history or collected by monitoring and audit systems. 3. While the process is running, another local principal with sufficient process-inspection access may read its arguments. 4. The attacker extracts the WeCom Bot secret. 5. The attacker uses the credential against the associated bot service where the credential is accepted. ### Impact Assessment Exposure compromises the confidentiality of the WeCom Bot secret. An attacker who obtains it may be able to authenticate as or operate the associated bot, subject to the permissions and controls applied by WeCom and OpenClaw. This does not inherently grant operating-system privilege escalation, but it can compromise the bot integration and its message-processing scope. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup_wecom.py:37
Finding

Interactive Secret Entry Is Displayed in the Terminal

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup_wecom.py:24
Finding

Plaintext Bot Secret Is Written Without Enforcing Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup_wecom.py:28
Finding

Direct Messaging Is Insecurely Configured as Open by Default

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file presents all user-facing instructions exclusively in Chinese, including setup, troubleshooting, and safety guidance. Under the policy for natural-language violations, forcing a specific language without giving the user a choice or documenting a justified locale constraint can be a policy issue.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to run npx clawhub@latest install wecom-ai-bot-setup, which fetches and executes the latest package version at runtime without pinning it. This creates a supply-chain risk: if the package or one of its delivery paths is compromised, users may execute unexpected code during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script stores the provided WeCom secret directly in a user configuration file on disk with no warning, no permission hardening, and no use of a safer secret store. If that file is readable by other local users, backed up insecurely, or later exposed through logs/support bundles, the bot credential could be stolen and abused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example values and instructions are written in Chinese ('你的 Bot ID', '你的 Secret', '保持现有模型配置'), which imposes a specific language in user-facing configuration guidance. There is no indication that Chinese is optional, selectable, or required for a region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

User-facing strings, prompts, help text, and docstrings are all presented in Chinese, which can impose a fixed language on users without indicating that language is configurable. The policy calls for flagging language/locale constraints when the skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.