T09 · Insecure Skill Coding Practices
- Location
engine.py:362- Finding
Private Conversation Data Is Persisted to Agent Memory Without Explicit Opt-In
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not a clear backdoor, but it profiles WeChat contacts and persists private message data with weak user controls.
Install only if you are authorized to process the relevant WeChat conversations and are comfortable with local plaintext reports plus long-term memory records containing contact names, inferred interests, scores, and message excerpts. Prefer simulated or manually reviewed use, keep auto-reply disabled unless explicitly approved, protect any WeChat cookie as a session secret, and avoid enabling memory or broad collection permissions until the skill adds clear consent, redaction, retention, and deletion controls.
engine.py:362Private Conversation Data Is Persisted to Agent Memory Without Explicit Opt-In
engine.py:398Raw Messages and Customer Profiles Are Stored in Unprotected Plaintext Files
Requirements.md:31Documented Tool Permissions Exceed the Needs of the Shipped Mock-Only Implementation
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
仅保留包含关键词的内容,如 "AI,机器人,chatbot" |
| --analysis_depth | enum | basic | 分析深度: basic/detailed/deep |
| --auto_reply | bool | false | 是否自动生成回复草稿 |
| --reply_template | string | 内置模板 | 回复模板,支持 {name}, {interest}, {product} 变量 |
# crontab 或 OpenClaw cron
openclaw cron add \
--name "每日 AI 群聊线索扫描" \
--schedule "0 9 * * *" \
--payload.agentTurn.message "用 wechat-lead-generation 抓取 groups 中最近 1 天的 AI 相关对话,生成报告" \
--delivery.announce.channel openclaw-weixin
# 先抓取分析,不自动回复
.agents/skills/wechat-lead-generation/bin/run \
--source friends \
--days_back 2 \
--analysis_depth deep
# 人工审核报告后,对高评分线索单独发送回复
out
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf output/wechat-lead-generation/*
The skill is explicitly designed to collect WeChat conversation data, analyze it for lead generation, and retain it in reports, artifacts, and memory. In this context, the combination of private messaging content, profiling, scoring, and retention materially increases surveillance and privacy risk, especially if used on contacts who did not consent to this secondary processing.
The report generator embeds excerpts of private message content and names into a shareable Markdown report. This makes sensitive conversations portable and easy to redistribute outside the original chat environment, increasing the likelihood of unauthorized disclosure or misuse.
The code writes customer profiles, high-scoring leads, and raw messages to local disk under a fixed workspace path, with no consent, notice, redaction, or access control. Because the data includes names and conversation excerpts from WeChat, this creates a clear privacy exposure and raises risk of unauthorized local access, accidental sharing, or policy noncompliance.
The skill sends lead information into an external memory layer without explicit disclosure, even though that information includes names, interests, scores, and summarized chat content. External or long-term memory use increases the chance of later reuse, leakage, or cross-context exposure of personal data beyond the original lead-generation task.
The memory storage logic persists identities and summarized chat content for future reuse, turning transient conversation analysis into long-term profiling. This broadens impact from a one-time lead report to ongoing retention and possible reuse in unrelated contexts, which is especially risky for personal communications data.
The artifacts export writes all profiles, high-scoring leads, and raw messages to disk, including original conversation data. Persisting full raw messages and associated profiles creates a concentrated local repository of sensitive communications that could be accessed by other processes, users, backups, or later operators.
The changelog explicitly advertises WeChat multi-channel data collection and historical storage, including friends, group chats, Moments, and public accounts, without any mention of consent, lawful basis, data minimization, retention limits, or protection of sensitive personal data. In a lead-generation skill, this omission increases the risk that operators will deploy privacy-invasive collection and persistence workflows that violate platform rules or privacy obligations.
The publishing guide is written as a directive in Chinese and provides no indication that users may choose another language or that the skill is restricted to a Chinese-speaking audience for a documented reason. This creates a natural-language locale policy concern because it effectively forces a specific language without opt-in.
The skill description is presented entirely in Chinese from the opening tagline onward, with no indication that language choice is optional or that the skill is region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The document instructs users to set a WECHAT_COOKIE environment variable for real data scraping but does not include any credential-handling, storage, rotation, or redaction guidance. Because a WeChat cookie is effectively an authenticated session token, accidental exposure through shell history, process listings, logs, screenshots, or shared terminal sessions could allow account takeover or unauthorized access to message data.
The skill describes capabilities that imply network access and file output, but it does not declare any explicit tool scope, permissions, or allowed-tools boundaries. In an agent environment, this creates a least-privilege failure: the skill can be invoked without clear constraints on what tools it may use for scraping, storage, and report generation.
The skill is explicitly designed to scrape WeChat friends, groups, moments, and articles, analyze conversation content for intent, and persist profiles in memory, yet the privacy discussion is limited to platform-terms and account-ban risk rather than informed consent, data minimization, or lawful basis for processing. This makes unauthorized collection, profiling, and retention of personal communications more likely, increasing the risk of privacy violations, sensitive-data exposure, and noncompliant surveillance/marketing use.
Natural-language strings, logs, report content, and generated replies are predominantly fixed in Chinese, and the default reply/report behavior does not offer locale selection or user opt-in. This can violate language or locale policy where skills must not force a language without giving the user a choice.
The skill’s stated function is lead capture, analysis, and reply generation, but it also persists lead records into a separate long-term memory system. That expands data retention and downstream reuse of sensitive WeChat conversation content and identities beyond the core workflow, creating privacy and compliance risk if operators or users were not explicitly informed.
The natural-language content for core feature descriptions is presented in Chinese only, which can amount to a language policy issue if users are not given a choice or the restriction is not justified. No opt-in, bilingual support, or region-specific rationale is provided in this file.
This markdown file uses Chinese for nearly all contributor instructions, which effectively forces a specific language for participation. Under the policy rule, locale or language constraints should either be optional, user-selectable, or clearly justified as region-specific.
No suspicious patterns detected.