Back to skill

Security audit

Wechat Claude Code Installer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent WeChat-to-Claude Code installer, but it asks users to run unverified remote code and creates a persistent local bridge with broad access to messages, files, commands, and credentials.

Review this carefully before installing. Use only a disposable or non-work WeChat account, avoid sensitive chats or files, do not store a real Anthropic key in a LaunchAgent plist, and only run the installer after auditing or pinning the upstream repository and npm dependencies. Treat the daemon as a local agent with the same file and command access as your user account.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.sh:22
Finding

Unpinned Remote Source and Dependency Code Is Installed and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fix-cwd.sh:7
Finding

Working-Directory Argument Is Injected into Executable Python Source

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fix-meta-talk.sh:6
Finding

Custom Prompt Is Injected into Executable Python Source

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:141
Finding

Documentation Stores a Long-Lived API Token in a Plaintext LaunchAgent File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (69)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented primarily as an installer/helper, but the content also includes persistent system modifications, launchd agent management, plist editing, and a full uninstall that deletes project/data directories. This description-behavior mismatch is dangerous because users may consent to setup assistance without realizing the skill also performs removal and persistent reconfiguration actions on their machine.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/check-upstream.sh (reported line 40)May include surrounding context.

sh
}

get_remote_latest() {
  /usr/bin/curl -s --max-time 10 "$API/commits/main" \
    | python3 -c "import json,sys; d=json.load(sys.stdin); print(d.get('sha','')[:7])" 2>/dev/null
}

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/check-upstream.sh (reported line 45)May include surrounding context.

sh
}

get_remote_latest() {
  /usr/bin/curl -s --max-time 10 "$API/commits/main" \
    | python3 -c "import json,sys; d=json.load(sys.stdin); print(d.get('sha','')[:7])" 2>/dev/null
}

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/check-upstream.sh (reported line 72)May include surrounding context.

sh
echo "Pin 版本: $pin_commit"
  echo ""
  echo "=== 自 pin 以来上游 commit ==="
  /usr/bin/curl -s --max-time 10 "$API/compare/$pin_commit...main" \
    | python3 -c "
import json, sys
try:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/doctor.sh (reported line 29)May include surrounding context.

sh
echo "2) Upstream wechat-claude-code"
if [ -d "$HOME/.claude/skills/wechat-claude-code" ]; then
  echo "   WARN already exists at ~/.claude/skills/wechat-claude-code"
  echo "        - first install: rm -rf and re-run install.sh"
  echo "        - upgrade: cd ~/.claude/skills/wechat-claude-code && git pull && npm install"
else
  echo "   OK not installed yet"

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/doctor.sh (reported line 50)May include surrounding context.

sh
# 4. ANTHROPIC_BASE_URL compliance check (most important)
echo "4) Anthropic API endpoint (compliance)"
BASE_URL="${ANTHROPIC_BASE_URL:-}"
if [ -z "$BASE_URL" ] && [ -f "$HOME/.claude/settings.json" ]; then
  BASE_URL=$(python3 -c "import json,sys; d=json.load(open('$HOME/.claude/settings.json')); print(d.get('env',{}).get('ANTHROPIC_BASE_URL',''))" 2>/dev/null || echo "")
fi
if [ -z "$BASE_URL" ]; then

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/doctor.sh (reported line 51)May include surrounding context.

sh
# 4. ANTHROPIC_BASE_URL compliance check (most important)
echo "4) Anthropic API endpoint (compliance)"
BASE_URL="${ANTHROPIC_BASE_URL:-}"
if [ -z "$BASE_URL" ] && [ -f "$HOME/.claude/settings.json" ]; then
  BASE_URL=$(python3 -c "import json,sys; d=json.load(open('$HOME/.claude/settings.json')); print(d.get('env',{}).get('ANTHROPIC_BASE_URL',''))" 2>/dev/null || echo "")
fi
if [ -z "$BASE_URL" ]; then

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/uninstall.sh (reported line 30)May include surrounding context.

sh
if [ -d ~/.claude/skills/wechat-claude-code ]; then
  echo "→ 删除上游项目..."
  rm -rf ~/.claude/skills/wechat-claude-code
fi

if [ -d ~/.wechat-claude-code ]; then

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/uninstall.sh (reported line 35)May include surrounding context.

sh
if [ -d ~/.claude/skills/wechat-claude-code ]; then
  echo "→ 删除上游项目..."
  rm -rf ~/.claude/skills/wechat-claude-code
fi

if [ -d ~/.wechat-claude-code ]; then

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/uninstall.sh (reported line 40)May include surrounding context.

sh
if [ -d ~/.claude/skills/wechat-claude-code ]; then
  echo "→ 删除上游项目..."
  rm -rf ~/.claude/skills/wechat-claude-code
fi

if [ -d ~/.wechat-claude-code ]; then

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/uninstall.sh (reported line 30)May include surrounding context.

sh
if [ -d ~/.claude/skills/wechat-claude-code ]; then
  echo "→ 删除上游项目..."
  rm -rf ~/.claude/skills/wechat-claude-code
fi

if [ -d ~/.wechat-claude-code ]; then

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/uninstall.sh (reported line 35)May include surrounding context.

sh
if [ -d ~/.wechat-claude-code ]; then
  echo "→ 删除数据目录..."
  rm -rf ~/.wechat-claude-code
fi

echo ""

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/uninstall.sh (reported line 40)May include surrounding context.

sh
echo ""
echo "✅ 卸载完成。本 skill 自身仍在 ~/.claude/skills/wechat-claude-code-installer/,"
echo "   如果也想删: rm -rf ~/.claude/skills/wechat-claude-code-installer/"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 17)May include surrounding context.

安装

bash
# Claude Code skills
mkdir -p ~/.claude/skills/wechat-claude-code-installer
cp SKILL.md ~/.claude/skills/wechat-claude-code-installer/

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 18)May include surrounding context.

bash
# Claude Code skills
mkdir -p ~/.claude/skills/wechat-claude-code-installer
cp SKILL.md ~/.claude/skills/wechat-claude-code-installer/

# 或者 ClawHub

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation phrases are very broad, natural-language triggers such as '装一下微信桥' and '微信里用 Claude Code', which can cause the skill to activate during ordinary conversation rather than through an explicit user request. Because this skill installs and configures a message bridge tied to WeChat, accidental activation could lead to unintended setup guidance or execution of sensitive workflow steps with privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises message bridging and bidirectional file transfer but does not present a prominent warning about the privacy and data-handling consequences. In this context, users may connect a personal or work WeChat account without understanding that messages, files, prompts, and possibly metadata could traverse third-party services, proxies, logs, or local daemons.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly instructs the agent to run shell commands, write configuration files, edit session.json/plist, clone repositories, and uninstall components, but the manifest declares no explicit tool scope or permissions. That creates an under-declared capability boundary, making it easier for an agent or reviewer to underestimate the skill's ability to modify the host system.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The repeated plist-focused finding at this line highlights the same issue: the skill encourages persistent modification of a launch agent configuration that carries sensitive runtime state. Because this bridge forwards WeChat content to Claude and can execute code locally, compromising its persistent configuration has meaningful privacy and integrity implications.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

如果 doctor 报告 ANTHROPIC_BASE_URL 指向公司代理,且不希望微信对话经过公司日志:

bash
PLIST=~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist
python3 <<'PY'
import plistlib, os
p = os.path.expanduser("~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist")

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The repeated plist-focused finding at this line highlights the same issue: the skill encourages persistent modification of a launch agent configuration that carries sensitive runtime state. Because this bridge forwards WeChat content to Claude and can execute code locally, compromising its persistent configuration has meaningful privacy and integrity implications.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

如果 doctor 报告 ANTHROPIC_BASE_URL 指向公司代理,且不希望微信对话经过公司日志:

bash
PLIST=~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist
python3 <<'PY'
import plistlib, os
p = os.path.expanduser("~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist")

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The code loads and rewrites the launch agent plist, modifying persistent environment variables for the daemon. Combined with the bridge's ability to read files, run commands, and forward chat content, persistent environment tampering can redirect traffic, change authorization context, or silently alter long-term daemon behavior across reboots.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

bash
PLIST=~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist
python3 <<'PY'
import plistlib, os
p = os.path.expanduser("~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist")
with open(p, 'rb') as f: d = plistlib.load(f)
env = d.setdefault('EnvironmentVariables', {})

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

This line explicitly writes an Anthropic authentication token into the launchd plist's EnvironmentVariables, creating persistent plaintext credential storage. If another local process, user, backup system, or support bundle can read the plist, the token can be stolen and used to access the user's Anthropic account or API resources.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
PLIST=~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist
python3 <<'PY'
import plistlib, os
p = os.path.expanduser("~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist")
with open(p, 'rb') as f: d = plistlib.load(f)
env = d.setdefault('EnvironmentVariables', {})
env['ANTHROPIC_AUTH_TOKEN'] = 'sk-ant-api03-你的key'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
with open(p, 'rb') as f: d = plistlib.load(f)
env = d.setdefault('EnvironmentVariables', {})
env['ANTHROPIC_AUTH_TOKEN'] = 'sk-ant-api03-你的key'
env['ANTHROPIC_BASE_URL'] = 'https://api.anthropic.com/v1/'
with open(p, 'wb') as f: plistlib.dump(d, f)
print("done")
PY

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

Writing the modified plist back to disk makes the daemon's configuration and any included secrets durable across restarts and potentially accessible to other local actors. In this skill's context, persistence is more dangerous because the daemon mediates messages and local command/file access, so compromised config has ongoing impact.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
env = d.setdefault('EnvironmentVariables', {})
env['ANTHROPIC_AUTH_TOKEN'] = 'sk-ant-api03-你的key'
env['ANTHROPIC_BASE_URL'] = 'https://api.anthropic.com/v1/'
with open(p, 'wb') as f: plistlib.dump(d, f)
print("done")
PY
launchctl unload ~/Library/LaunchAgents/com.wechat-claude-code.bridge.plist

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/check-upstream.sh (reported line 17)May include surrounding context.

sh
UPSTREAM_DIR="$HOME/.claude/skills/wechat-claude-code"
PIN_FILE="$SKILL_DIR/.upstream-pin"
REPO="Wechat-ggGitHub/wechat-claude-code"
API="https://api.github.com/repos/$REPO"

usage() {
  cat <<EOF

Static analysis

No suspicious patterns detected.