Back to skill

Security audit

Pyweixin Rpa

Security checks for vulnerabilities and agentic risk

Overview

This WeChat automation skill is not clearly malicious, but it needs review because it can export private WeChat data and perform account-changing actions with limited built-in consent controls.

Install only if you intentionally want an agent to operate your logged-in Windows WeChat account. Before use, require explicit confirmation for sending, posting, clearing history, accepting friends or groups, exporting chats/files, or claiming red packets; use a dedicated virtual environment with pinned dependencies; and avoid using it for bulk outreach, surveillance, or platform-rule evasion.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Unpinned Third-Party Dependencies Are Installed from the Ambient Package Index

Content
View full analysis
=5.9.5 pyautogui>=0.9.54 pycaw>=20240210 pywin32>=308 pywin32-ctypes>=0.2.2 pywinauto>=0.6.8 pillow>=10.4.0 emoji>=2.14.1 sounddevice>=0.5.1 soundfile>=0.13.1 packaging>=23.2 ``` `metadata.openclaw.yaml:46-54`: ```yaml setup: check_requirements: script: scripts/check_requirements.py cwd: . output_format: json success_key: missing_package run_once: true on_missing: action: install command: pip install -r scripts/requirements.txt ``` `SKILL.md:43-51`: ```bash python scripts/check_requirements.py ``` ```bash pip install -r scripts/requirements.txt ``` ### Technical Analysis The dependency manifest uses minimum-version constraints rather than exact, reviewed versions. Consequently, pip may install any future release satisfying the constraints. The installation command also lacks hash verification, an explicitly trusted package index, and an isolated environment requirement. Python packages can execute code during installation through build backends and later during import. Therefore, compromise of an allowed package release, its publisher account, a configured package index, or the local pip configuration could introduce code that was not present during this audit. This finding does not establish that any currently named dependency is malicious. The vulnerability is the absence of controls that bind installation to reviewed artifacts. ### Attack Path 1. The Skill runs `scripts/check_requirements.py` during initial setup. 2. One or more dependencies are reported as missing. 3. The agent follows the documented setup workflow and executes: `pip install -r scripts/re ...[truncated 931 chars]
Remediation
View remediation
pyautogui== ``` 2. Generate and verify cryptographic hashes for every package and transitive dependency. 3. Install with hash enforcement: ```bash python -m pip install --require-hashes -r scripts/requirements.txt ``` 4. Use a controlled, authenticated package mirror or explicitly document an approved index rather than relying on ambient pip configuration. 5. Install dependencies inside a dedicated virtual environment with no unnecessary privileges. 6. Maintain a lock file that includes transitive dependencies and review updates before changing it. 7. Add automated dependency scanning and provenance checks to the release process. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/pyweixin/WinSettings.py:169
Finding

Long Message Content Is Persisted in a Predictable Plaintext File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (166)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented import surface includes system-level capabilities such as clipboard manipulation, input-method handling, power/sleep behavior, audio/device control, and general file operations that materially exceed the stated WeChat automation scope. Hidden or under-disclosed desktop-control features increase the risk of misuse for data exfiltration, stealthy interaction, or broader host manipulation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented import surface includes system-level capabilities such as clipboard manipulation, input-method handling, power/sleep behavior, audio/device control, and general file operations that materially exceed the stated WeChat automation scope. Hidden or under-disclosed desktop-control features increase the risk of misuse for data exfiltration, stealthy interaction, or broader host manipulation.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
- **scripts/requirements.txt** — 依赖清单

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
- **scripts/requirements.txt** — 依赖清单

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
auto | 源码中某一处控件未在微信相关窗口中定位到 | 出现该异常后不要重试,直接结束相关自动化任务。总结异常信息,将未定位到的 UI 控件具体位置返回(`scripts/pyweixin/Uielements.py`),并建议用户使用 `inspect.exe` 等工具查看未定位到的控件信息,将信息反馈后修改定位

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
auto | 源码中某一处控件未在微信相关窗口中定位到 | 出现该异常后不要重试,直接结束相关自动化任务。总结异常信息,将未定位到的 UI 控件具体位置返回(`scripts/pyweixin/Uielements.py`),并建议用户使用 `inspect.exe` 等工具查看未定位到的控件信息,将信息反馈后修改定位

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The API documents clearing chat history without a clear irreversible-action warning, confirmation requirement, or backup guidance. Because chat records may be evidentiary or business-critical, accidental or malicious triggering could cause permanent data loss.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module provides extensive primitives for collecting, exporting, and persisting private chats, contacts, media, group membership, and Moments content at scale. In the context of an automation skill, this creates a broad surveillance and exfiltration capability that is highly sensitive even if intended for legitimate RPA use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function can automatically approve new friends and optionally clear the associated verification records, changing the account's trust boundary without strong safeguards. Automatically expanding a user's contact list can enable impersonation, spam acceptance, privacy exposure, and social-graph manipulation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code can automatically discover and accept group invitation links from chat history, causing unsolicited account-state changes that are not described in the manifest. This is dangerous because it can silently join the user to new groups, increasing exposure to spam, social engineering, data leakage, and persistent account changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module implements automatic red-packet grabbing, which is a payment-adjacent action not disclosed in the skill description. Because it can autonomously claim financial-value items from chats, this materially raises risk beyond normal messaging automation and could violate user expectations or platform policy.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The skill advertises code-driven behavior that can read and write files, but the manifest does not declare any explicit tool scope or permission boundaries. This creates an authorization ambiguity where an agent may invoke broader filesystem actions than a reviewer or user would reasonably expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill can send messages and files and modify contacts or Moments, but the description lacks a clear warning that these are externally visible, state-changing actions on the user's WeChat account. Without explicit user-warning and confirmation requirements, an agent could perform irreversible or privacy-impacting actions unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs the agent to run pip install, which grants package-management and code-fetching capability beyond the declared messaging automation role. Installing dependencies at runtime can introduce supply-chain risk, execute unreviewed setup code, and alter the host environment in ways the user did not explicitly authorize.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The import list exposes Windows system settings functionality, including clipboard and input-method operations, which are broader than the manifest's stated WeChat automation purpose. These capabilities can interact with sensitive user data or system state and therefore should not be silently bundled into a narrowly described communication skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document gives operational guidance for exposing and automating WeChat’s otherwise restricted UI through accessibility behavior, but does so without meaningful warnings about privacy, account enforcement, or platform-policy risks. In the context of an RPA skill specifically meant to automate Windows WeChat, this normalizes potentially unauthorized automation and increases the chance of misuse against user accounts, contacts, and message data.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section provides a step-by-step method to bypass WeChat UI access restrictions by enabling Narrator before login, waiting, and reusing the behavior until internal UI structures remain visible. That is effectively evasion guidance for defeating an application's anti-automation protections, which is dangerous because it enables unauthorized control of messaging, contacts, and other sensitive client features.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document discusses account-based restriction behavior after WeChat updates and advises 'reasonable' use so as not to trigger limits, which functions as operational advice for sustaining an unauthorized access method. In a skill built for WeChat RPA, this makes the content more dangerous because it helps users adapt to detection and maintain automation over protected UI surfaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation clearly enables extraction of chat history, which can contain highly sensitive communications, with no prominent warning or consent boundary. In an automation skill, this creates a straightforward path to bulk collection of private message content and metadata.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Across the reference, the skill exposes broad capabilities to collect private messages, contact details, files, profile data, and social activity in plain language with little emphasis on minimization or consent. In a capable agent environment, this substantially increases the risk of surveillance, bulk extraction, and misuse of personal data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance encourages obtaining full chat-record contents when a flag is enabled, which normalizes escalation from counts to raw message data. That design increases the chance that an agent collects far more sensitive content than needed for the user's task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Saving media and files from chats to local disk creates a clear data-exfiltration and retention risk, especially when target folders may be user-accessible or synchronized elsewhere. The documentation does not prominently warn that private user data will be written outside the chat client.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API documents bulk retrieval of sensitive personal profile data, including identifiers and contact details, without prominent privacy, consent, or minimization guidance. In an agent skill context, this materially increases the risk of unauthorized collection and downstream disclosure of personal data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic approval of new friend requests affects account integrity and trust relationships, yet the documentation presents it as a normal operation without warning. An agent or script using this blindly could admit unwanted contacts, spam accounts, or social-engineering footholds.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Posting to Moments publishes user-visible content to the user's social graph, but the documentation lacks a prominent warning about the visibility and reputational consequences. In an agent setting, an unintended call could create unauthorized public-facing posts under the user's identity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.