T03 · Remote Payload Retrieval and Execution
- Location
scripts/install.sh:22- Finding
Unpinned Remote Source and Dependency Code Is Installed and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent WeChat-to-Claude Code installer, but it asks users to run unverified remote code and creates a persistent local bridge with broad access to messages, files, commands, and credentials.
Review this carefully before installing. Use only a disposable or non-work WeChat account, avoid sensitive chats or files, do not store a real Anthropic key in a LaunchAgent plist, and only run the installer after auditing or pinning the upstream repository and npm dependencies. Treat the daemon as a local agent with the same file and command access as your user account.
scripts/install.sh:22Unpinned Remote Source and Dependency Code Is Installed and Executed
scripts/fix-cwd.sh:7Working-Directory Argument Is Injected into Executable Python Source
scripts/fix-meta-talk.sh:6Custom Prompt Is Injected into Executable Python Source
SKILL.md:141Documentation Stores a Long-Lived API Token in a Plaintext LaunchAgent File
The skill is presented primarily as an installer/helper, but the content also includes persistent system modifications, launchd agent management, plist editing, and a full uninstall that deletes project/data directories. This description-behavior mismatch is dangerous because users may consent to setup assistance without realizing the skill also performs removal and persistent reconfiguration actions on their machine.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
}
get_remote_latest() {
/usr/bin/curl -s --max-time 10 "$API/commits/main" \
| python3 -c "import json,sys; d=json.load(sys.stdin); print(d.get('sha','')[:7])" 2>/dev/null
}
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
}
get_remote_latest() {
/usr/bin/curl -s --max-time 10 "$API/commits/main" \
| python3 -c "import json,sys; d=json.load(sys.stdin); print(d.get('sha','')[:7])" 2>/dev/null
}
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
echo "Pin 版本: $pin_commit"
echo ""
echo "=== 自 pin 以来上游 commit ==="
/usr/bin/curl -s --max-time 10 "$API/compare/$pin_commit...main" \
| python3 -c "
import json, sys
try:
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
echo "2) Upstream wechat-claude-code"
if [ -d "$HOME/.claude/skills/wechat-claude-code" ]; then
echo " WARN already exists at ~/.claude/skills/wechat-claude-code"
echo " - first install: rm -rf and re-run install.sh"
echo " - upgrade: cd ~/.claude/skills/wechat-claude-code && git pull && npm install"
else
echo " OK not installed yet"
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
# 4. ANTHROPIC_BASE_URL compliance check (most important)
echo "4) Anthropic API endpoint (compliance)"
BASE_URL="${ANTHROPIC_BASE_URL:-}"
if [ -z "$BASE_URL" ] && [ -f "$HOME/.claude/settings.json" ]; then
BASE_URL=$(python3 -c "import json,sys; d=json.load(open('$HOME/.claude/settings.json')); print(d.get('env',{}).get('ANTHROPIC_BASE_URL',''))" 2>/dev/null || echo "")
fi
if [ -z "$BASE_URL" ]; then
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
# 4. ANTHROPIC_BASE_URL compliance check (most important)
echo "4) Anthropic API endpoint (compliance)"
BASE_URL="${ANTHROPIC_BASE_URL:-}"
if [ -z "$BASE_URL" ] && [ -f "$HOME/.claude/settings.json" ]; then
BASE_URL=$(python3 -c "import json,sys; d=json.load(open('$HOME/.claude/settings.json')); print(d.get('env',{}).get('ANTHROPIC_BASE_URL',''))" 2>/dev/null || echo "")
fi
if [ -z "$BASE_URL" ]; then
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
if [ -d ~/.claude/skills/wechat-claude-code ]; then
echo "→ 删除上游项目..."
rm -rf ~/.claude/skills/wechat-claude-code
fi
if [ -d ~/.wechat-claude-code ]; then
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
if [ -d ~/.claude/skills/wechat-claude-code ]; then
echo "→ 删除上游项目..."
rm -rf ~/.claude/skills/wechat-claude-code
fi
if [ -d ~/.wechat-claude-code ]; then
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
if [ -d ~/.claude/skills/wechat-claude-code ]; then
echo "→ 删除上游项目..."
rm -rf ~/.claude/skills/wechat-claude-code
fi
if [ -d ~/.wechat-claude-code ]; then
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
if [ -d ~/.claude/skills/wechat-claude-code ]; then
echo "→ 删除上游项目..."
rm -rf ~/.claude/skills/wechat-claude-code
fi
if [ -d ~/.wechat-claude-code ]; then
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
if [ -d ~/.wechat-claude-code ]; then
echo "→ 删除数据目录..."
rm -rf ~/.wechat-claude-code
fi
echo ""
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
echo ""
echo "✅ 卸载完成。本 skill 自身仍在 ~/.claude/skills/wechat-claude-code-installer/,"
echo " 如果也想删: rm -rf ~/.claude/skills/wechat-claude-code-installer/"
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
# Claude Code skills
mkdir -p ~/.claude/skills/wechat-claude-code-installer
cp SKILL.md ~/.claude/skills/wechat-claude-code-installer/
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Claude Code skills
mkdir -p ~/.claude/skills/wechat-claude-code-installer
cp SKILL.md ~/.claude/skills/wechat-claude-code-installer/
# 或者 ClawHub
The invocation phrases are very broad, natural-language triggers such as '装一下微信桥' and '微信里用 Claude Code', which can cause the skill to activate during ordinary conversation rather than through an explicit user request. Because this skill installs and configures a message bridge tied to WeChat, accidental activation could lead to unintended setup guidance or execution of sensitive workflow steps with privacy implications.
The README advertises message bridging and bidirectional file transfer but does not present a prominent warning about the privacy and data-handling consequences. In this context, users may connect a personal or work WeChat account without understanding that messages, files, prompts, and possibly metadata could traverse third-party services, proxies, logs, or local daemons.
The skill clearly instructs the agent to run shell commands, write configuration files, edit session.json/plist, clone repositories, and uninstall components, but the manifest declares no explicit tool scope or permissions. That creates an under-declared capability boundary, making it easier for an agent or reviewer to underestimate the skill's ability to modify the host system.
The repeated plist-focused finding at this line highlights the same issue: the skill encourages persistent modification of a launch agent configuration that carries sensitive runtime state. Because this bridge forwards WeChat content to Claude and can execute code locally, compromising its persistent configuration has meaningful privacy and integrity implications.
如果 doctor 报告 ANTHROPIC_BASE_URL 指向公司代理,且不希望微信对话经过公司日志:
PLIST=~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist
python3 <<'PY'
import plistlib, os
p = os.path.expanduser("~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist")
The repeated plist-focused finding at this line highlights the same issue: the skill encourages persistent modification of a launch agent configuration that carries sensitive runtime state. Because this bridge forwards WeChat content to Claude and can execute code locally, compromising its persistent configuration has meaningful privacy and integrity implications.
如果 doctor 报告 ANTHROPIC_BASE_URL 指向公司代理,且不希望微信对话经过公司日志:
PLIST=~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist
python3 <<'PY'
import plistlib, os
p = os.path.expanduser("~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist")
The code loads and rewrites the launch agent plist, modifying persistent environment variables for the daemon. Combined with the bridge's ability to read files, run commands, and forward chat content, persistent environment tampering can redirect traffic, change authorization context, or silently alter long-term daemon behavior across reboots.
PLIST=~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist
python3 <<'PY'
import plistlib, os
p = os.path.expanduser("~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist")
with open(p, 'rb') as f: d = plistlib.load(f)
env = d.setdefault('EnvironmentVariables', {})
This line explicitly writes an Anthropic authentication token into the launchd plist's EnvironmentVariables, creating persistent plaintext credential storage. If another local process, user, backup system, or support bundle can read the plist, the token can be stolen and used to access the user's Anthropic account or API resources.
PLIST=~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist
python3 <<'PY'
import plistlib, os
p = os.path.expanduser("~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist")
with open(p, 'rb') as f: d = plistlib.load(f)
env = d.setdefault('EnvironmentVariables', {})
env['ANTHROPIC_AUTH_TOKEN'] = 'sk-ant-api03-你的key'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
with open(p, 'rb') as f: d = plistlib.load(f)
env = d.setdefault('EnvironmentVariables', {})
env['ANTHROPIC_AUTH_TOKEN'] = 'sk-ant-api03-你的key'
env['ANTHROPIC_BASE_URL'] = 'https://api.anthropic.com/v1/'
with open(p, 'wb') as f: plistlib.dump(d, f)
print("done")
PY
Writing the modified plist back to disk makes the daemon's configuration and any included secrets durable across restarts and potentially accessible to other local actors. In this skill's context, persistence is more dangerous because the daemon mediates messages and local command/file access, so compromised config has ongoing impact.
env = d.setdefault('EnvironmentVariables', {})
env['ANTHROPIC_AUTH_TOKEN'] = 'sk-ant-api03-你的key'
env['ANTHROPIC_BASE_URL'] = 'https://api.anthropic.com/v1/'
with open(p, 'wb') as f: plistlib.dump(d, f)
print("done")
PY
launchctl unload ~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
UPSTREAM_DIR="$HOME/.claude/skills/wechat-claude-code"
PIN_FILE="$SKILL_DIR/.upstream-pin"
REPO="Wechat-ggGitHub/wechat-claude-code"
API="https://api.github.com/repos/$REPO"
usage() {
cat <<EOF
No suspicious patterns detected.