Back to skill

Security audit

WeChat Read CN

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to read WeChat chats, but it handles private messages with weak conversation checks and unsafe temporary screenshot storage, so it needs review before installation.

Review this carefully before installing. Use it only on a Mac/account where you are comfortable granting Accessibility and Screen Recording access, and only for chats you are authorized to read. Be aware it can leave private screenshots and contact text in /tmp and may select the wrong conversation when search results or OCR are ambiguous.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wechat_read.sh:103
Finding

Ambiguous OCR Verification Can Capture the Wrong Conversation

Content
View full analysis
0 )); then similarity=$(( match_chars * 100 / total_chars )) fi if (( similarity >= VERIFY_SIMILARITY_THRESHOLD )); then log "✅ 相似度匹配通过" return 0 fi ``` ### Technical Analysis The chat-content verification is fail-open. Any nonempty OCR output is accepted unless it contains one of a small number of rejection phrases. If no timestamp or positive identity evidence is found, the function explicitly returns success. The title similarity algorithm does not compare character order, adjacency, frequency, or edit distance. It counts a contact-name character as matched whenever that character occurs anywhere in the OCR result. Repeated characters may all be counted based on one occurrence in the title. With the threshold set to 60%, short names and contacts with overlapping characters can produce false-positive verification. These checks are security-sensitive because successful verification immediately autho ...[truncated 1436 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wechat_read.sh:15
Finding

Sensitive Chat Data Is Written to Predictable Shared Temporary Paths

Content
View full analysis
/tmp/wechat_read_clip.txt osascript -e 'set the clipboard to (read POSIX file "/tmp/wechat_read_clip.txt" as "utf8")' } ``` ```bash capture_page() { local page_num="$1" local outfile="${PAGE_PREFIX}${page_num}.png" screencapture -x -R "${CHAT_X},${CHAT_Y},${CHAT_W},${CHAT_H}" "$outfile" \ || fail "Cannot capture page $page_num" echo "$outfile" } ``` ```bash if [[ "$MODE" == "capture" || "$MODE" == "auto" ]]; then rm -f /tmp/wechat_read_p*.png /tmp/wechat_read_search.png 2>/dev/null || true fi ``` ### Technical Analysis The scripts place contact names, verification screenshots, search results, and full chat screenshots under fixed names in `/tmp`. They do not create a private temporary directory, set a restrictive `umask`, use exclusive file creation, verify ownership, or install an exit handler that removes sensitive data. The shell redirection used for `/tmp/wechat_read_clip.txt` follows an existing symbolic link. A local attacker who can prepare that predictable path can redirect the write to another file writable by the victim account. Predictable screenshot paths also permit pre-creation, monitoring, and potential tampering, depending on the destination utility's handling of existing links an ...[truncated 1854 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Ssd 3

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script explicitly directs the agent to read, OCR, deduplicate, and reconstruct full private chat content from screenshots. Even if this is the intended feature, it handles highly sensitive personal communications and creates a substantial confidentiality risk if used without strict consent, minimization, and retention controls.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/wechat_read.sh (reported line 532)May include surrounding context.

sh
# ── Clean up old captures (only on first capture) ───────────────────
if [[ "$MODE" == "capture" || "$MODE" == "auto" ]]; then
    rm -f /tmp/wechat_read_p*.png /tmp/wechat_read_search.png 2>/dev/null || true
fi

case "$MODE" in

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/wechat_read_v2.0_backup.sh (reported line 441)May include surrounding context.

sh
# ── Clean up old captures (only on first capture) ───────────────────
if [[ "$MODE" == "capture" || "$MODE" == "auto" ]]; then
    rm -f /tmp/wechat_read_p*.png /tmp/wechat_read_search.png 2>/dev/null || true
fi

case "$MODE" in

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/wechat_read_v2.1.sh (reported line 516)May include surrounding context.

sh
# ── Clean up old captures (only on first capture) ───────────────────
if [[ "$MODE" == "capture" || "$MODE" == "auto" ]]; then
    rm -f /tmp/wechat_read_p*.png /tmp/wechat_read_search.png 2>/dev/null || true
fi

case "$MODE" in

Ssd 3

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

Next-page mode instructs the agent to keep inspecting chat screenshots until a specific participant's messages are found, encouraging iterative review of potentially large amounts of private conversation content. This can expose more historical data than necessary and materially increases the scope of sensitive information processed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This skill is explicitly designed to read private WeChat chat history by taking screenshots of on-screen conversations and performing OCR, but the description does not prominently warn about the privacy sensitivity of the action or require clear user confirmation before accessing message content. In practice, this can lead to unintended collection or disclosure of highly sensitive personal or business communications, especially because the skill automates screen capture and stores images in predictable temporary paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script captures private WeChat chat screenshots and OCR-derived content into predictable files under /tmp, a shared temporary location that may be accessible to other local processes or users depending on system configuration and timing. Because this skill is specifically designed to extract conversation history, the context materially increases the sensitivity of the data being written, making leakage of personal messages a real privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script stores chat screenshots and contact-related artifacts in predictable paths under /tmp, which can expose sensitive private conversation data to other local processes or users on the machine. Because these files persist outside the app boundary and are not securely permissioned or reliably deleted, this creates unnecessary local data leakage risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Copying the contact name into the system clipboard overwrites the user's clipboard contents and exposes potentially sensitive contact identifiers to other applications that monitor clipboard data. This creates avoidable privacy leakage beyond the minimum needed to automate the UI.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The fallback path asks the agent to inspect a captured WeChat search screenshot, which may reveal contact names, avatars, groups, or other sensitive metadata unrelated to the exact requested target. This broadens exposure beyond the minimum needed and increases privacy risk during error handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs OCR on screenshots of WeChat chats without an explicit privacy notice or consent checkpoint, which means highly sensitive message content is being processed and logged by automation in a way users may not expect. Because this skill's whole purpose is extracting conversation history, the absence of a clear warning makes the privacy implications more dangerous, not less.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill stores screenshots of private WeChat conversations under predictable filenames in /tmp, which can unnecessarily expose sensitive chat content to other local processes, later users of the same machine, backups, or forensic recovery. In the context of a chat-reading skill, the captured data is inherently sensitive, so weak temporary-file hygiene materially increases privacy risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest scopes this skill to reading or retrieving WeChat conversation history from a contact or group. In --next-page mode, the script explicitly instructs the agent to stop when it finds '对方(左侧白色)气泡', which operationalizes analysis of sender-side message bubbles rather than just capturing requested history pages. This slightly extends behavior from passive history capture into agent-directed conversation-role inspection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest scopes this skill to reading WeChat chat history via screenshots and OCR, but the code writes arbitrary contact text into the system clipboard before pasting it into WeChat. While used to drive UI automation, modifying the global clipboard is a broader capability than simple reading and is not declared in the description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest describes screenshot capture plus agent OCR, but the implementation additionally invokes the local Swift toolchain for OCR and repeatedly drives AppleScript/System Events for UI control. UI automation is broadly implied by the desktop-client workflow, but runtime code execution via Swift is not clearly declared and is a stronger capability than the description suggests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.