Back to skill

Security audit

wechat-chat-analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real local WeChat analysis tool, but it reads and stores highly sensitive chats in plaintext by default, including populated runtime chat data bundled with the package.

Review carefully before installing. This skill can read private WeChat conversations and will write raw chat content to local cache/report files by default; the package also already contains populated runtime data. Only use it if you are comfortable with local plaintext retention of sensitive conversations and can delete or clean the data files after use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/analyze_chat.py:114
Finding

Private Chat Transcripts Are Persisted and Exported in Plaintext by Default

Content
View full analysis
CACHE_TTL: return None return entry.get("raw") def set_cached_export(chat_target, limit, raw_content): """保存导出缓存""" ensure_data_dir() key = _cache_key(chat_target, limit) try: if os.path.exists(CACHE_FILE): with open(CACHE_FILE, "r", encoding="utf-8") as f: cache = json.load(f) else: cache = {} except (json.JSONDecodeError, OSError): cache = {} cache[key] = {"ts": time_module.time(), "raw": raw_content} with open(CACHE_FILE, "w", encoding="utf-8") as f: json.dump(cache, f, ensure_ascii=False) ``` Raw transcript inclusion is enabled unconditionally by default: ```python parser.add_argument("--include-raw", action="store_true", default=True, help="输出中包含原始聊天记录(默认包含)") ``` The raw export is then copied into the generated report: ```python if args.include_raw: lines.append("\n--- 原始聊天记录 ---") lines.append(raw) lines.append("--- 原始聊天记录结束 ---") ``` ### Technical Analysis The Skill handles highly sensitive private chat records but writ ...[truncated 3228 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose says structured local chat analysis, but the documented behavior expands into active-chat scanning, persistent history and feedback storage, and inclusion of raw chat content. This mismatch is dangerous because users and policy layers may consent to limited analysis while the skill actually performs broader surveillance and retention on highly sensitive relationship data.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/analyze_chat.py (reported line 84)May include surrounding context.

python
ident = hashlib.md5(str(args).encode()).hexdigest()[:8]
    temp_path = os.path.join(tempfile.gettempdir(), f"_wct_{os.getpid()}_{ident}.txt")
    cmd = [exe] + args
    env = {**os.environ, "PYTHONIOENCODING": "utf-8"}
    with open(temp_path, "w", encoding="utf-8") as f:
        r = subprocess.run(cmd, stdout=f, stderr=subprocess.PIPE,
                           text=True, encoding="utf-8", errors="replace",

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill is presented as a structured analysis tool, but it appends the full raw chat transcript to the generated report by default via --include-raw with default=True. That creates unnecessary exposure of highly sensitive personal communications in output files, increasing the chance of unintended disclosure, downstream reuse, or exfiltration by other tools reading the report.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs use of shell, environment variables, and file read/write against sensitive local WeChat data but declares no explicit tool scope or permission boundaries. That creates an over-privileged execution model where an agent could access or persist private data without clear user-visible constraints or enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger language is broad enough to overlap with ordinary conversation about messaging advice, which can cause the agent to invoke a sensitive local-data skill when the user only wanted generic help. In this context, accidental activation can expose private chat records and relationship analysis without sufficiently informed intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill lacks a prominent warning that it will inspect extremely sensitive private chats and may persist derived history and feedback. Without a clear notice, users may not appreciate the privacy impact of relationship inference, active-session scanning, and local retention.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The real-time mode includes ambiguous and subjective activation criteria like the agent deciding the user is 'currently chatting'. That invites unprompted access to recent sensitive messages based on inference rather than explicit user authorization.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The multi-user scan trigger allows broad phrases and even agent-initiated scanning of active chats, which expands access from one named conversation to many contacts without a tightly bounded request. In a private messaging context, enumerating active contacts and unread status is itself sensitive surveillance data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatically saving analysis snapshots of private chat history across runs creates an unnecessary retention surface for intimate content and behavioral inferences. Stored history can be exfiltrated later, accessed by other local processes, or reused outside the user's original expectation of one-time analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The framework instructs exporting and analyzing local WeChat chat records, which are highly sensitive personal communications that may include intimate, financial, health, and third-party information. There is no accompanying privacy warning, consent guidance, data minimization, or handling restriction, which increases the risk of over-collection and inappropriate processing of both the user's and another person's private data.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/analyze_chat.py (reported line 86)May include surrounding context.

python
cmd = [exe] + args
    env = {**os.environ, "PYTHONIOENCODING": "utf-8"}
    with open(temp_path, "w", encoding="utf-8") as f:
        r = subprocess.run(cmd, stdout=f, stderr=subprocess.PIPE,
                           text=True, encoding="utf-8", errors="replace",
                           env=env)
    with open(temp_path, "r", encoding="utf-8") as f:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Exported chat content is cached to disk for 60 seconds in export_cache.json without explicit disclosure, meaning sensitive message content is stored outside the immediate command flow. Temporary retention still increases exposure to local compromise, forensic recovery, or accidental reuse by later commands.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persists chat-derived history snapshots and user feedback to local JSON files beyond the immediate analysis session. Even though the saved snapshots are more limited than raw messages, they still retain relationship and communication metadata over time without clear retention controls or user consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The who_is_hot feature enumerates recent sessions and unread chats to discover active private conversations, which exceeds the narrow purpose of analyzing a user-specified conversation. This broadens access from one targeted chat to many conversations and leaks contact names, activity timing, and message previews into generated output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script exports chat records and embeds them in an output file by default without a prominent user-facing privacy warning. Because chat content is highly sensitive, default export-and-write behavior can surprise users and leave private data in temp or user-specified files accessible to other local processes or users.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Persisting per-contact analysis history and feedback turns a transient analysis tool into a retention system for intimate communication metadata and derived inferences. Even if data stays local, long-term storage increases exposure to later compromise, unintended reuse, or access by other tools or users on the machine.

Content

No source excerpt is available for this finding.

Ssd 3

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Recording feedback history for later optimization establishes ongoing storage of user interaction data that can reveal preferences, relationship context, or behavioral patterns over time. While less sensitive than raw chats, it still increases privacy risk through accumulation and secondary use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON file includes natural-language values in Chinese (for example, the rating value "好") with no surrounding documentation or metadata indicating that Chinese is optional, user-selected, or required for a region-specific purpose. Under the language/locale policy check, hard-coded natural-language content can indicate a forced locale when no opt-in or justification is present.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This JSON file includes natural-language keys such as "春天的雨" and "啊 这", which implies the skill data is tied to Chinese-language content. Because the file provides no indication that this is an optional locale or a justified region-specific dataset, it may conflict with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The document title and all instructional/output text are in Chinese, including fixed Chinese output templates. This suggests a language-specific behavior without any explicit opt-in or explanation that the skill is intentionally limited to Chinese-speaking users or a China-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module docstring, argument descriptions, and status/error messages are all written in Chinese, with no mechanism for the user to select another language. This is a natural-language locale constraint that is not documented as region-specific or optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.