T09 · Insecure Skill Coding Practices
- Location
scripts/wechat_send_hello.py:194- Finding
Recipient Verification Failure Can Cause Message Misdelivery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its WeChat automation purpose, but it can send to many recipients and retain sensitive message, contact, and screen-capture data without enough confirmation or privacy controls.
Review before installing. Use this only for accounts and recipient lists you control, manually verify recipients, avoid confidential message bodies, keep contact files and logs private, and prefer disabling screenshots unless needed. Treat batch modes as real outbound messaging, not a harmless test workflow.
scripts/wechat_send_hello.py:194Recipient Verification Failure Can Cause Message Misdelivery
scripts/wechat_send_campaign.py:92Contacts and Complete Message Bodies Are Stored in Plaintext
scripts/wechat_send_hello.py:127Full-Desktop Screenshots Can Capture Unrelated Sensitive Information
SKILL.md:25Third-Party Python Dependencies Are Installed Without Version or Integrity Pinning
The documented behavior includes diagnostic screenshots, control-tree dumps, and optional OCR extraction, but these sensitive data-collection capabilities are not prominently declared as part of the skill's effective behavior. In a desktop messaging context, screenshots and OCR can capture unrelated conversations, contact names, and other on-screen private data, making this substantially more dangerous than ordinary send automation.
The documented behavior includes diagnostic screenshots, control-tree dumps, and optional OCR extraction, but these sensitive data-collection capabilities are not prominently declared as part of the skill's effective behavior. In a desktop messaging context, screenshots and OCR can capture unrelated conversations, contact names, and other on-screen private data, making this substantially more dangerous than ordinary send automation.
The skill advertises desktop automation that clearly implies shell execution and file read/write behavior, but it does not declare any tool scope or permissions boundaries. This is dangerous because an agent may invoke the skill with broader capabilities than the user expects, enabling unintended local file access, log creation, and command execution without explicit consent or policy review.
The skill describes batch and personalized message workflows but lacks a clear warning that it can contact multiple recipients in sequence and persist logs, screenshots, and summaries on disk. In a messaging automation skill, that omission increases the risk of accidental mass outreach, privacy leakage, and forensic persistence of sensitive communications data.
This documentation explicitly supports serial/batch templated messaging to multiple WeChat recipients using contact lists with personalized fields, but it provides no warning, consent requirement, rate limiting guidance, or privacy/compliance considerations. In the context of a desktop messaging automation skill, this omission increases the risk of spam, unintended bulk outreach, misuse of personal data in CSV/JSON files, and account/platform enforcement issues.
The script immediately iterates over all provided recipients and sends messages without any explicit pre-dispatch confirmation, dry-run review, or user acknowledgment of recipient count/content. In a desktop automation context, this increases the risk of accidental mass messaging, unintended outreach, or abuse if the input file is wrong or the skill is triggered with unreviewed data.
The results structure stores each recipient's contact and full message, and save_summary writes that data to disk in JSON, while logging also records recipient names. This creates a clear privacy and data leakage risk because sensitive message content and recipient identities may persist in logs/results files beyond the sending session and be exposed to other local users, backups, or support workflows.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
exe = find_wechat_exe()
if not exe:
raise FileNotFoundError("没找到 WeChat.exe,请手动修改 WECHAT_PATHS")
subprocess.Popen([exe])
logging.info("已启动微信,等待加载...")
time.sleep(6)
The screenshot helper captures and saves the full desktop on failures and during verification, potentially collecting sensitive information from unrelated applications and notifications. Because the images are written to disk, the exposure persists beyond runtime and can be accessed later by other users, tools, or backups.
Full-screen screenshots are collected and stored without meaningful notice, scoping, or redaction, so the skill may silently retain sensitive desktop content unrelated to WeChat. This is especially risky in an automation tool because failures may happen unexpectedly while confidential material is visible on screen.
The optional OCR verification captures the entire desktop and extracts all visible text, which can include unrelated chats, emails, documents, passwords, or other sensitive on-screen data. That exceeds the narrow purpose of sending a WeChat message and creates an unnecessary data-collection capability with privacy and confidentiality risk.
OCR over a full-screen capture extracts potentially all visible text on the desktop without clear notice or minimization, which can expose sensitive data far beyond the intended message verification task. The added text extraction step increases risk because it turns incidental visual exposure into searchable, loggable content.
This script persists a per-recipient campaign summary containing contact identifiers, rendered message bodies, missing template fields, timestamps, and error details to disk in JSON. In a messaging automation context, that creates a clear privacy and confidentiality risk because recipient lists and personalized outbound content may include sensitive personal or business data, and the script does not present an explicit warning, consent step, minimization, or retention control before storing it locally.
The CSV rows use Chinese names and message text, which indicates a fixed language/locale in the file content. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation, and no opt-in or justification is present here.
The sample data uses Chinese-language values for names and company fields, which can indicate a language-specific default in user-facing content. Because no surrounding text offers a language choice or explains that the file is region-specific, this may conflict with a policy requiring language or locale neutrality unless justified.
Natural-language strings shown to users, including the program description and argument help text, are only provided in Chinese. This imposes a specific language on users without any apparent opt-in or alternative locale support.
The manifest focuses on chat opening and message sending, but this debug feature prints and persists the full WeChat control hierarchy. That exposes a broader introspection capability into application UI state than is justified by the normal operational purpose.
No suspicious patterns detected.