Back to skill

Security audit

微信操作手册

Security checks for vulnerabilities and agentic risk

Overview

This skill automates WeChat Moments but also includes unconfirmed message-sending and voice-call actions outside its browsing purpose.

Review before installing. Use this only for narrow, supervised WeChat navigation if you are comfortable with coordinate-based desktop automation, and do not allow it to send messages, post comments, like content, or place calls unless a human confirms the exact recipient and action immediately beforehand.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:138
Finding

Unconfirmed Fixed-Coordinate Automation Can Trigger Unintended Calls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:138-149
Vulnerability Type: Unsafe UI automation without target, focus, or user-confirmation validation
Risk Level: Medium

Complete Code Snippet

powershell
[WMoments]::SetCursorPos(1055, 108)
Start-Sleep -Milliseconds 50
[WMoments]::mouse_event(2, 0, 0, 0, 0)
[WMoments]::mouse_event(4, 0, 0, 0, 0)

Start-Sleep -Milliseconds 200
Add-Type -AssemblyName System.Windows.Forms
[System.Windows.Forms.SendKeys]::SendWait("{DOWN}")
[System.Windows.Forms.SendKeys]::SendWait("{ENTER}")

Technical Analysis

The skill initiates a voice call by injecting a global mouse click at a hardcoded screen coordinate and then sending keyboard input to whichever window currently owns focus. It does not verify:

  • That WeChat is the foreground application.
  • That the intended conversation is open.
  • That coordinate (1055, 108) currently represents the call control.
  • That the selected menu entry is a voice-call action.
  • That the user has explicitly approved the external communication.

Fixed coordinates are sensitive to display resolution, scaling, window placement, application updates, transient dialogs, and focus changes. The short timing delays do not provide synchronization or state validation. Consequently, the click and subsequent DOWN and ENTER inputs may activate unrelated controls in WeChat or another application.

The same section also documents blind keyboard-driven messaging behavior, increasing the general risk of unintended external actions when focus or target selection is incorrect. This is an insecure skill coding practice rather than a permission escalation: the automation acts with the authority of the currently logged-in desktop user without ensuring that the resulting action matches the user's intent.

Attack Path

  1. The user or agent opens a conversation and invokes the documented call workflow.
  2. Before the injected input i ...[truncated 1465 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit user confirmation immediately before initiating any call or sending any message. Display the verified contact and proposed action in the confirmation prompt.
  2. Replace absolute-coordinate input with application-specific accessibility or UI Automation APIs that identify controls by window, role, name, and hierarchy.
  3. Verify that the foreground process and window belong to WeChat before every external action.
  4. Verify the selected conversation and recipient through readable UI state rather than relying on prior keyboard input.
  5. Inspect and validate that the call menu is open and that the intended voice-call entry is selected before activation.
  6. Abort safely if focus changes, expected controls are absent, the application layout is unknown, or validation times out.
  7. Avoid global SendKeys for consequential operations. Use scoped automation interfaces that target a specific verified window and control.
  8. Separate navigation from consequential actions: opening a page may be automatic, but sending messages, placing calls, posting comments, or recording reactions should require a distinct approval step.
  9. Add rate limits, structured audit logging, and a dry-run mode that identifies the intended recipient and action without executing it.
  10. Test across supported resolutions, scaling settings, window states, and application versions; disable the workflow on unsupported configurations.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is presented as a WeChat Moments browsing tool, but the documented capabilities extend into contact search, direct message sending, and voice calling. That scope expansion enables real-world actions affecting third parties and user accounts, which is dangerous because an agent invoking the skill for benign browsing could instead message or call someone without clear authorization.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The direct-message sending code uses SendKeys to transmit text and press Enter, which can send communications to unintended recipients if window focus or search results are wrong. In the context of a Moments skill, this capability is unjustified and materially increases the risk of unauthorized outreach, impersonation, spam, or social engineering.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The markdown includes message sending and phone-call placement steps but provides no explicit warning that these cause external, user-visible actions affecting other people. In a consumer communication app, omission of such warnings increases the likelihood of accidental transmission, unintended contact, and abuse by downstream automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The voice-calling instructions automate initiation of a call through UI clicks and keystrokes, creating a direct real-world action with privacy, financial, and harassment implications. Because the skill is nominally for browsing Moments, adding call initiation is out of scope and increases the chance of unauthorized or accidental calls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description uses broad scenarios such as opening, browsing, viewing friends' posts, and liking/commenting without defining trigger constraints, authorization boundaries, or what actions are allowed automatically. Ambiguous scope makes it easier for an agent to over-invoke the skill or interpret it as permission to perform additional account actions, especially in a live messaging application.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.