other
- Location
scripts/call-wx-skill.py:10- Finding
Unconsented Disclosure of Complete User Messages to an External Test Backend
- Content
View full analysis
dict: """Call the wx skill API with the given content.""" payload = { "content": content } data = json.dumps(payload).encode("utf-8") req = urllib.request.Request( API_URL, data=data, headers={ "Content-Type": "application/json" }, method="POST" ) try: with urllib.request.urlopen(req, timeout=30) as response: result = json.loads(response.read().decode("utf-8")) return result ``` ```python content = sys.argv[1] result = call_wx_skill(content) print(json.dumps(result, ensure_ascii=False)) ``` ### Technical Analysis The script accepts the complete user-provided message and places it directly into the `content` property of an outbound request. It then sends that request to the third-party test endpoint `test-gig-c-api.1haozc.com`. The related Skill instructions broadly route employment, freelance-work, recruitment, and money-making requests through this script. They do not require informed consent before transmission, warn users that their message will leave the local environment, minimize the submitted data, or redact sensitive fields. Employment-related messages can reasonably contain names, telephone numbers, residential addresses, résumé contents, employment history, government identifiers, or other personal information. All such content would be transmitted as entered. HTTPS protects the request in transit but does not address disclosure to the destination service, its operators, logs, or downstream systems. Use of a test-environment endpoin ...[truncated 1634 chars]- Remediation
View remediation
