T09 · Insecure Skill Coding Practices
- Location
scripts/wechat_read.sh:103- Finding
Ambiguous OCR Verification Can Capture the Wrong Conversation
- Content
View full analysis
0 )); then similarity=$(( match_chars * 100 / total_chars )) fi if (( similarity >= VERIFY_SIMILARITY_THRESHOLD )); then log "✅ 相似度匹配通过" return 0 fi ``` ### Technical Analysis The chat-content verification is fail-open. Any nonempty OCR output is accepted unless it contains one of a small number of rejection phrases. If no timestamp or positive identity evidence is found, the function explicitly returns success. The title similarity algorithm does not compare character order, adjacency, frequency, or edit distance. It counts a contact-name character as matched whenever that character occurs anywhere in the OCR result. Repeated characters may all be counted based on one occurrence in the title. With the threshold set to 60%, short names and contacts with overlapping characters can produce false-positive verification. These checks are security-sensitive because successful verification immediately autho ...[truncated 1436 chars]- Remediation
View remediation
