Back to skill

Security audit

Weixin Plugin Installer

Security checks for vulnerabilities and agentic risk

Overview

The skill is broadly coherent for an admin Weixin setup workflow, but it performs high-impact local actions with confirmed implementation risks.

Install only on a controlled admin host, review the Weixin plugin version before use, and expect the workflow to write QR/login artifacts, change OpenClaw plugin state, and restart the gateway after successful pairing. Avoid using it on shared systems until file permissions, PID validation, and the restart scheduler are hardened.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
scripts/install_weixin_connection.sh:57
Finding

Unpinned Third-Party Plugin Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/schedule_gateway_restart.sh:16
Finding

Shell Command Injection Through OPENCLAW_STATE_DIR

Content
View full analysis
> '$RESTART_LOG_FILE' 2>&1 rm -f '$RESTART_PID_FILE' " >/dev/null 2>&1 & ``` ### Technical Analysis `RESTART_LOG_FILE` and `RESTART_PID_FILE` are derived from the environment-controlled `OPENCLAW_STATE_DIR`. They are then interpolated directly into a double-quoted command string passed to `bash -lc`. Although the generated paths are surrounded by single quotes inside the nested command, the script does not reject a single quote in `OPENCLAW_STATE_DIR`. A crafted value can terminate the intended single-quoted path and append shell syntax. The resulting injected syntax is parsed by the second Bash process when the delayed restart is scheduled. The issue arises from composing executable shell source code with untrusted data. Quoting in the outer shell does not make the interpolated value safe after it becomes part of the source interpreted by the inner shell. ### Attack Path 1. An attacker gains control over `OPENCLAW_STATE_DIR` in the environment used to invoke the Skill. 2. The attacker assigns a value containing a single quote followed by shell syntax. 3. The login workflow detects text interpreted as a successful connection and invokes `schedule_gateway_restart.sh`, or the scheduler is otherwise invoked through the legitimate workflow. 4. The crafted path is inserted into the string supplie ...[truncated 613 chars]
Remediation
View remediation
>"$RESTART_LOG_FILE" 2>&1 rm -f -- "$RESTART_PID_FILE" ) /dev/null 2>&1 & ``` - If a child shell is unavoidable, pass paths as positional arguments rather than interpolating them into executable source. - Validate `OPENCLAW_STATE_DIR` against an explicit path policy and reject control characters, shell metacharacters, and unexpected relative paths. - Use `--` for file-manipulation commands where supported. - Run the Skill under a dedicated least-privileged account to limit the consequences of any command-execution flaw. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/refresh_weixin_qr.sh:15
Finding

Sensitive QR and Login Artifacts Created Without Enforced Permissions

Content
View full analysis
"$LOG_FILE" ``` ```python with open(args.input, "r", encoding="utf-8", errors="ignore") as f: raw = f.read() clean = strip_ansi(raw) lines = clean.splitlines(True) blocks = find_all_qr_blocks(lines) selected = choose_latest_block(blocks) if not selected: print("qr block not found", file=sys.stderr) sys.exit(1) os.makedirs(os.path.dirname(args.png), exist_ok=True) with open(args.txt, "w", encoding="utf-8") as f: f.write("\n".join(selected["block"]) + "\n") matrix = block_to_matrix(selected["block"]) write_png_bw(matrix, args.png, scale=12) ``` ```python with open(args.json, "w", encoding="utf-8") as f: json.dump(payload, f, ensure_ascii=False) ``` The PNG writer similarly creates the QR image with the process's default creation mode: ```python with open(out_path, "wb") as f: f.write(png) ``` ### Technical Analysis The QR image, text representation, metadata, and raw login log contain sensitive authentication material. A pairing QR code is effectively a short-lived credential because a party that obtains and scans it may participate in account binding. The scripts do not establish a restrictive `umask`, assign explicit file permissions, or verify the permissions of existing directories and files. Consequently, the resulting access modes depend on the host process's inherited umask and pre-existing filesystem state. On a shared system with a permissive umask, these artifacts may be r ...[truncated 1159 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/refresh_weixin_qr.sh:54
Finding

Unverified PID Files Can Terminate Unrelated Processes

Content
View full analysis
/dev/null } stop_old_active_login() { if [[ -f "$ACTIVE_PID_FILE" ]]; then old_pid="$(cat "$ACTIVE_PID_FILE" 2>/dev/null || true)" if is_pid_running "${old_pid:-}"; then kill "$old_pid" 2>/dev/null || true sleep 1 if is_pid_running "${old_pid:-}"; then kill -9 "$old_pid" 2>/dev/null || true fi fi fi } ``` From `scripts/cancel_weixin_qr.sh`: ```bash is_pid_running() { local pid="$1" [[ -n "${pid:-}" ]] && kill -0 "$pid" 2>/dev/null } if [[ ! -d "$SESSION_DIR" ]]; then emit_json false "not_found" "没有找到活动会话" exit 0 fi if [[ -f "$ACTIVE_PID_FILE" ]]; then pid="$(cat "$ACTIVE_PID_FILE" 2>/dev/null || true)" if is_pid_running "${pid:-}"; then kill "$pid" 2>/dev/null || true sleep 1 if is_pid_running "${pid:-}"; then kill -9 "$pid" 2>/dev/null || true fi fi fi ``` ### Technical Analysis The scripts treat the integer stored in `active_login.pid` as sufficient proof of process identity. `kill -0` establishes only that a process with that PID exists and is signalable; it does not establish that the process is the Weixin login process originally launched by the Skill. If the original process exits and the operating system reuses its PID, a later refresh or cancellation can signal an unrelated process. The same outcome is possible if a same-user attacker can alter or replace the PID file. The fallback to `SIGKILL` increases the potential impact because the target cannot perform cleanup or save state. The implementation also does not validate that the PID is a strictly positive decimal value, compare process start ti ...[truncated 1252 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to avoid hard restarts in-chat, but the implementation reportedly schedules and performs gateway restarts, manages PID/log files, and runs delayed background tasks. Hidden service-control behavior is security-relevant because it can disrupt availability, create persistence-like background activity, and exceed the principle of least surprise for a chat-triggered admin skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to avoid hard restarts in-chat, but the implementation reportedly schedules and performs gateway restarts, manages PID/log files, and runs delayed background tasks. Hidden service-control behavior is security-relevant because it can disrupt availability, create persistence-like background activity, and exceed the principle of least surprise for a chat-triggered admin skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill schedules a gateway restart as a side effect of successful login, but that service-management capability is not disclosed in the skill description. Hidden restart behavior can disrupt unrelated sessions or services and broadens the skill's authority beyond QR/login handling.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

After detecting login success, the script automatically triggers a gateway restart, creating an undocumented operational side effect. In an agent skill, undisclosed service restarts are dangerous because they can cause denial of service, interrupt other automations, and bypass user expectations about the skill's scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation states that after WeChat connection succeeds, the skill will asynchronously execute a Gateway restart, but it does not clearly warn the administrator in the user-facing flow that a background restart will occur. This can cause unexpected service interruption, break active sessions, or disrupt the current messaging path if operators do not anticipate the restart timing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill instructs the agent to execute local scripts and handle QR/image/text artifacts, but it does not declare an explicit tool scope such as allowed-tools or permissions. That ambiguity increases the risk that an agent/runtime grants broader file read/write access than intended, especially since the workflow references reading generated files and emitting local media paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description, allowed intents, required user-facing replies, and reply style are all specified in Chinese, and the trigger examples are also Chinese-only. This imposes a language constraint on usage and responses without any opt-in, fallback, or documented justification that the skill is intentionally region- or language-specific.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This shell script kills a running process, including with SIGKILL, and then deletes state files, but it provides no confirmation prompt, warning message, or explanatory comments before doing so. Under the code-file criteria, destructive or irreversible operations should have some form of user disclosure unless the warning is present in accompanying markdown, which is not visible here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script emits multiple user-facing status messages in Chinese only, including explicit instructions such as asking the user to send the Chinese phrase “刷新微信二维码”. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script emits only Chinese user-facing instructions, including telling the user to send the Chinese phrase “刷新微信二维码”. This imposes a specific language for interaction without any opt-in or documented locale constraint, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script emits multiple hard-coded Chinese status messages to users, such as the responses at L045, L152, L157, L162, and L180. This imposes a specific language on all users without opt-in or an explained region-specific constraint, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script reads a PID from a state file and forcefully terminates that process, including with SIGKILL, without verifying that the PID still belongs to the expected prior login command. If the PID file is stale, corrupted, or attacker-controlled within the same user context, the skill could kill an unrelated process, exceeding its stated QR-refresh purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script launches openclaw channels login --channel openclaw-weixin in a background shell, which is a subprocess operation that can affect authentication state. In this file there is no comment, prompt, or visible disclosure before starting that command; the user only sees status after the operation has already begun.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/schedule_gateway_restart.sh (reported line 37)May include surrounding context.

sh
fi
fi

nohup bash -lc "
sleep '$DELAY_SECONDS'
{
  printf '[%s] openclaw gateway restart\n' \"\$(date -u +\"%Y-%m-%dT%H:%M:%SZ\")\"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code schedules a background subprocess with nohup bash -lc, executes openclaw gateway restart, appends to a log file, and writes/removes a PID file. While there is internal logging to a file, there is no visible user-facing disclosure, prompt, or explanatory comment/docstring warning that the script will restart the gateway asynchronously and modify files under the state directory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script returns natural-language status messages only in Chinese, which imposes a specific language on users without offering a choice or documenting a locale-specific constraint. This matches the policy category for language or locale restrictions without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code writes a generated PNG to a user-supplied path, and similar file writes also occur for the text and JSON outputs. Although file output is part of the script's purpose, the code provides no confirmation prompt, comment, docstring, or user-facing message disclosing that it will create or overwrite files at the specified paths.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.