T09 · Insecure Skill Coding Practices
- Location
SKILL.md:138- Finding
Unconfirmed Fixed-Coordinate Automation Can Trigger Unintended Calls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:138-149
Vulnerability Type: Unsafe UI automation without target, focus, or user-confirmation validation
Risk Level: MediumComplete Code Snippet
powershell [WMoments]::SetCursorPos(1055, 108) Start-Sleep -Milliseconds 50 [WMoments]::mouse_event(2, 0, 0, 0, 0) [WMoments]::mouse_event(4, 0, 0, 0, 0) Start-Sleep -Milliseconds 200 Add-Type -AssemblyName System.Windows.Forms [System.Windows.Forms.SendKeys]::SendWait("{DOWN}") [System.Windows.Forms.SendKeys]::SendWait("{ENTER}")Technical Analysis
The skill initiates a voice call by injecting a global mouse click at a hardcoded screen coordinate and then sending keyboard input to whichever window currently owns focus. It does not verify:
- That WeChat is the foreground application.
- That the intended conversation is open.
- That coordinate
(1055, 108)currently represents the call control. - That the selected menu entry is a voice-call action.
- That the user has explicitly approved the external communication.
Fixed coordinates are sensitive to display resolution, scaling, window placement, application updates, transient dialogs, and focus changes. The short timing delays do not provide synchronization or state validation. Consequently, the click and subsequent
DOWNandENTERinputs may activate unrelated controls in WeChat or another application.The same section also documents blind keyboard-driven messaging behavior, increasing the general risk of unintended external actions when focus or target selection is incorrect. This is an insecure skill coding practice rather than a permission escalation: the automation acts with the authority of the currently logged-in desktop user without ensuring that the resulting action matches the user's intent.
Attack Path
- The user or agent opens a conversation and invokes the documented call workflow.
- Before the injected input i ...[truncated 1465 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit user confirmation immediately before initiating any call or sending any message. Display the verified contact and proposed action in the confirmation prompt.
- Replace absolute-coordinate input with application-specific accessibility or UI Automation APIs that identify controls by window, role, name, and hierarchy.
- Verify that the foreground process and window belong to WeChat before every external action.
- Verify the selected conversation and recipient through readable UI state rather than relying on prior keyboard input.
- Inspect and validate that the call menu is open and that the intended voice-call entry is selected before activation.
- Abort safely if focus changes, expected controls are absent, the application layout is unknown, or validation times out.
- Avoid global
SendKeysfor consequential operations. Use scoped automation interfaces that target a specific verified window and control. - Separate navigation from consequential actions: opening a page may be automatic, but sending messages, placing calls, posting comments, or recording reactions should require a distinct approval step.
- Add rate limits, structured audit logging, and a dry-run mode that identifies the intended recipient and action without executing it.
- Test across supported resolutions, scaling settings, window states, and application versions; disable the workflow on unsupported configurations.
