T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:17- Finding
Blanket Sandbox Bypass for WeChat CLI Operations
- Content
View full analysis
**⚠️ Sandbox restriction** > > wx-cli reads from `~/.wx-cli/` (config, cache, daemon socket) and from WeChat's data directory (`~/Library/Containers/com.tencent.xinWeChat/` on macOS). Both paths are outside Claude Code's default sandbox. Every `wx` command in this skill needs to run with `dangerouslyDisableSandbox: true` from the start — don't waste a sandbox attempt first. The user can use `/sandbox` to view/edit restrictions. ``` ### Technical Analysis The Skill requires every invocation of the external `wx` executable to run with `dangerouslyDisableSandbox: true`. Access to the WeChat data directory and `~/.wx-cli` is necessary for the declared summarization functionality, but disabling the entire sandbox grants substantially broader access than those specific paths require. The invoked executable is not included in this project, so its implementation and effective behavior cannot be verified by auditing this Skill. Once the sandbox is disabled, the process may potentially access unrelated user files, local credentials, authentication tokens, browser profiles, SSH keys, environment variables, and network resources available to the current account. This creates a security boundary failure even though the Skill itself does not contain an explicit exfiltration command. The risk materializes if the external executable is compromised, replaced, or resolved through an attacker-controlled `PATH`. ### Attack Path 1. An attacker compromises the installed `wx` package, replaces the local executable, or places a malicious executable earlier in `PATH`. 2. The user invokes the Skill to summarize a WeChat group. 3. Following the Skill instructions, the Agent runs `wx` with `dangerouslyDisableSandbox: true`. 4. The attacker-controlled proce ...[truncated 990 chars]- Remediation
View remediation
