Back to skill

Security audit

WeChat Desktop Sender

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its WeChat automation purpose, but it can send to many recipients and retain sensitive message, contact, and screen-capture data without enough confirmation or privacy controls.

Review before installing. Use this only for accounts and recipient lists you control, manually verify recipients, avoid confidential message bodies, keep contact files and logs private, and prefer disabling screenshots unless needed. Treat batch modes as real outbound messaging, not a harmless test workflow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/wechat_send_hello.py:194
Finding

Recipient Verification Failure Can Cause Message Misdelivery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wechat_send_campaign.py:92
Finding

Contacts and Complete Message Bodies Are Stored in Plaintext

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wechat_send_hello.py:127
Finding

Full-Desktop Screenshots Can Capture Unrelated Sensitive Information

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:25
Finding

Third-Party Python Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The documented behavior includes diagnostic screenshots, control-tree dumps, and optional OCR extraction, but these sensitive data-collection capabilities are not prominently declared as part of the skill's effective behavior. In a desktop messaging context, screenshots and OCR can capture unrelated conversations, contact names, and other on-screen private data, making this substantially more dangerous than ordinary send automation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The documented behavior includes diagnostic screenshots, control-tree dumps, and optional OCR extraction, but these sensitive data-collection capabilities are not prominently declared as part of the skill's effective behavior. In a desktop messaging context, screenshots and OCR can capture unrelated conversations, contact names, and other on-screen private data, making this substantially more dangerous than ordinary send automation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises desktop automation that clearly implies shell execution and file read/write behavior, but it does not declare any tool scope or permissions boundaries. This is dangerous because an agent may invoke the skill with broader capabilities than the user expects, enabling unintended local file access, log creation, and command execution without explicit consent or policy review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes batch and personalized message workflows but lacks a clear warning that it can contact multiple recipients in sequence and persist logs, screenshots, and summaries on disk. In a messaging automation skill, that omission increases the risk of accidental mass outreach, privacy leakage, and forensic persistence of sensitive communications data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This documentation explicitly supports serial/batch templated messaging to multiple WeChat recipients using contact lists with personalized fields, but it provides no warning, consent requirement, rate limiting guidance, or privacy/compliance considerations. In the context of a desktop messaging automation skill, this omission increases the risk of spam, unintended bulk outreach, misuse of personal data in CSV/JSON files, and account/platform enforcement issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script immediately iterates over all provided recipients and sends messages without any explicit pre-dispatch confirmation, dry-run review, or user acknowledgment of recipient count/content. In a desktop automation context, this increases the risk of accidental mass messaging, unintended outreach, or abuse if the input file is wrong or the skill is triggered with unreviewed data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The results structure stores each recipient's contact and full message, and save_summary writes that data to disk in JSON, while logging also records recipient names. This creates a clear privacy and data leakage risk because sensitive message content and recipient identities may persist in logs/results files beyond the sending session and be exposed to other local users, backups, or support workflows.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/wechat_send_hello.py (reported line 87)May include surrounding context.

python
exe = find_wechat_exe()
    if not exe:
        raise FileNotFoundError("没找到 WeChat.exe,请手动修改 WECHAT_PATHS")
    subprocess.Popen([exe])
    logging.info("已启动微信,等待加载...")
    time.sleep(6)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The screenshot helper captures and saves the full desktop on failures and during verification, potentially collecting sensitive information from unrelated applications and notifications. Because the images are written to disk, the exposure persists beyond runtime and can be accessed later by other users, tools, or backups.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Full-screen screenshots are collected and stored without meaningful notice, scoping, or redaction, so the skill may silently retain sensitive desktop content unrelated to WeChat. This is especially risky in an automation tool because failures may happen unexpectedly while confidential material is visible on screen.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The optional OCR verification captures the entire desktop and extracts all visible text, which can include unrelated chats, emails, documents, passwords, or other sensitive on-screen data. That exceeds the narrow purpose of sending a WeChat message and creates an unnecessary data-collection capability with privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

OCR over a full-screen capture extracts potentially all visible text on the desktop without clear notice or minimization, which can expose sensitive data far beyond the intended message verification task. The added text extraction step increases risk because it turns incidental visual exposure into searchable, loggable content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This script persists a per-recipient campaign summary containing contact identifiers, rendered message bodies, missing template fields, timestamps, and error details to disk in JSON. In a messaging automation context, that creates a clear privacy and confidentiality risk because recipient lists and personalized outbound content may include sensitive personal or business data, and the script does not present an explicit warning, consent step, minimization, or retention control before storing it locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The CSV rows use Chinese names and message text, which indicates a fixed language/locale in the file content. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation, and no opt-in or justification is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The sample data uses Chinese-language values for names and company fields, which can indicate a language-specific default in user-facing content. Because no surrounding text offers a language choice or explains that the file is region-specific, this may conflict with a policy requiring language or locale neutrality unless justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language strings shown to users, including the program description and argument help text, are only provided in Chinese. This imposes a specific language on users without any apparent opt-in or alternative locale support.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest focuses on chat opening and message sending, but this debug feature prints and persists the full WeChat control hierarchy. That exposes a broader introspection capability into application UI state than is justified by the normal operational purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.