Back to skill

Security audit

Wechat Send

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to send WeChat messages, but it needs review because it can automatically send real messages after weak verification and leaves private message or screenshot data in predictable temporary files.

Review carefully before installing. Only use it if you are comfortable granting Accessibility control to automate the live WeChat desktop client, and avoid sensitive messages until it adds secure temporary files, cleanup, stronger recipient verification, and an explicit final confirmation of recipient and content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wechat_send.sh:19
Finding

Predictable Temporary Files Expose Sensitive Message and Contact Data

Content
View full analysis
&2; exit 1; } command -v cliclick >/dev/null || fail "cliclick not found. Install: brew install cliclick" clip_write() { # Write text to clipboard via temp file (safe for CJK + multiline) local text="$1" printf '%s' "$text" > /tmp/wechat_send_clip.txt osascript -e 'set the clipboard to (read POSIX file "/tmp/wechat_send_clip.txt" as "utf8")' } ``` The same predictable screenshot paths are later written directly: ```bash screencapture -x -R "50,50,1200,150" "$SCREENSHOT_TITLE" || fail "Cannot capture title screenshot" ``` ```bash screencapture -x -R "50,50,500,600" "$SCREENSHOT_DROPDOWN" || fail "Cannot capture dropdown screenshot" ``` ### Technical Analysis The script stores message text and WeChat screenshots under fixed, globally predictable `/tmp` paths. It does not: - Create the files atomically. - Use a private temporary directory. - Set a restrictive `umask`. - verify file ownership or reject symbolic links. - Remove the files after use. The shell redirection to `/tmp/wechat_send_clip.txt` follows a pre-existing symbolic link. Consequently, a local user who can create this path before the Skill runs may redirect the write to another file writable by the victim. The predictable files also retain plaintext message content, contact names, and captured portions of the WeChat interface after execution. The actual ability to read files may depend on the operating system's temporary-directory and default permissi ...[truncated 1430 chars]
Remediation
View remediation
"$CLIP_FILE" || fail "Cannot create clipboard file" osascript -e \ "set the clipboard to (read POSIX file \"$CLIP_FILE\" as \"utf8\")" rm -f -- "$CLIP_FILE" } ``` 3. Maintain file permissions of `0600` and directory permissions of `0700`. 4. Do not reuse stable filenames across executions. 5. Remove clipboard data immediately after it is read. 6. Retain screenshots only when fallback analysis is required and remove them as soon as fallback processing completes. 7. If artifacts must be retained, verify that each file is a regular file owned by the current user and is not a symbolic link. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wechat_send.sh:143
Finding

Weak OCR Recipient Verification Can Send Messages to the Wrong Conversation

Content
View full analysis
0 )); then similarity=$(( match_chars * 100 / total_chars )) fi log "相似度: ${similarity}% (阈值: ${VERIFY_SIMILARITY_THRESHOLD}%)" if (( similarity >= VERIFY_SIMILARITY_THRESHOLD )); then log "✅ 相似度匹配通过" return 0 fi ``` A successful result immediately authorizes message delivery: ```bash if verify_contact "$contact"; then # ✅ Verified — proceed to step 5 log "【步骤 3】✅ 验证通过,跳到步骤 5" send_message "$message" ``` ### Technical Analysis The script performs OCR over a broad `1200x150` screen region instead of obtaining an authoritative conversation identifier from the WeChat accessibility hierarchy. The exact-match check accepts the contact string anywhere in the OCR output. It does not establish that the matching text belongs to the active conversation title rather than a search field, button, notification, or other interface element. The similarity algorithm is weaker: - It ignores character order. - It ignores character position. - It only tests whether each contact character occurs somewhere in the entire OCR result. - Repeated characters in the contact name can be counted multiple times based on one occurrence in the OCR output. - A threshold of only 60% permits substantial differences. - It does not detect a ...[truncated 1948 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is triggered by broadly phrased messaging intents and operates a live WeChat UI to send messages, but the boundaries are not tight enough to ensure the request is specifically for WeChat sending rather than adjacent tasks like reading, replying in another app, or drafting only. Because the action is externally side-effecting and irreversible once sent, ambiguous invocation increases the chance of unintended message transmission to a real contact or group.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documentation describes automatic execution flow but does not prominently warn that it will control the macOS WeChat client via Accessibility/UI automation and immediately send a live message. Without an explicit user-facing warning, users or upstream agents may treat it like a draft/composition helper rather than a real-world action, raising the risk of accidental transmission, privacy violations, or social engineering abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script writes contact/message content to a predictable file in /tmp, which can expose sensitive data to other local processes or users depending on system configuration and timing. Because the file is not uniquely named, permission-hardened, or cleaned up, it also increases the risk of residual data leakage and symlink-related file clobbering.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script captures a portion of the WeChat window and runs OCR over the title area to verify the selected chat, which is a form of reading UI content despite the skill description claiming it is not for reading messages. Even if limited to chat-title verification, this processes potentially sensitive contact/group names and creates a mismatch between stated behavior and actual data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Screenshots of the WeChat UI are stored in predictable /tmp paths, which may contain contact names, search terms, and other private interface data. These files can persist after execution and be accessible to other local actors or accidentally reused, creating unnecessary privacy exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The fallback path captures a larger search-dropdown screenshot and instructs an agent to analyze it, exposing contact names and search results that the user may not expect to be read. This directly contradicts the claim that the skill is not for reading messages and increases privacy risk by handing UI contents to another analysis step.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Multiple user-facing log messages and instructions are hardcoded in Chinese, which imposes a language choice without opt-in. This can violate language/locale policy when the skill is intended for broader use and does not document or offer a language selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.