Back to skill

Security audit

WeChat Lead Generation

Security checks for vulnerabilities and agentic risk

Overview

The skill is not a clear backdoor, but it profiles WeChat contacts and persists private message data with weak user controls.

Install only if you are authorized to process the relevant WeChat conversations and are comfortable with local plaintext reports plus long-term memory records containing contact names, inferred interests, scores, and message excerpts. Prefer simulated or manually reviewed use, keep auto-reply disabled unless explicitly approved, protect any WeChat cookie as a session secret, and avoid enabling memory or broad collection permissions until the skill adds clear consent, redaction, retention, and deletion controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
engine.py:362
Finding

Private Conversation Data Is Persisted to Agent Memory Without Explicit Opt-In

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
engine.py:398
Finding

Raw Messages and Customer Profiles Are Stored in Unprotected Plaintext Files

Content
View full analysis
= 80] high_score_path = ARTIFACTS_DIR / 'high_score_leads.json' with open(high_score_path, 'w', encoding='utf-8') as f: json.dump(high_score, f, ensure_ascii=False, indent=2) logger.info(f"✅ 保存 high_score_leads: {high_score_path}") # 3. raw_messages.json - 原始抓取数据 raw_path = ARTIFACTS_DIR / 'raw_messages.json' with open(raw_path, 'w', encoding='utf-8') as f: json.dump(self.raw_data, f, ensure_ascii=False, indent=2) logger.info(f"✅ 保存 raw_messages: {raw_path}") ``` The destination directories are created without explicitly enforcing owner-only permissions: ```python WORKSPACE = Path('/Users/tom/.openclaw/workspace') OUTPUT_DIR = WORKSPACE / 'output' / 'wechat-lead-generation' OUTPUT_DIR.mkdir(parents=True, exist_ok=True) ARTIFACTS_DIR = OUTPUT_DIR / 'artifacts' ARTIFACTS_DIR.mkdir(parents=True, exist_ok=True) ``` The Markdown report is likewise written as plaintext: ```python report_path.write_text(content, encoding='utf-8') ``` ### Technical Analysis The Skill serializes complete raw messages, names, inferred interests, engagement information, timestamps, group names, article titles, and lead scores into plaintext Markdown and JSON artifacts. It does not explicitly set restrictive permissions, encrypt files ...[truncated 1656 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
Requirements.md:31
Finding

Documented Tool Permissions Exceed the Needs of the Shipped Mock-Only Implementation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 92)May include surrounding context.

仅保留包含关键词的内容,如 "AI,机器人,chatbot" | | --analysis_depth | enum | basic | 分析深度: basic/detailed/deep | | --auto_reply | bool | false | 是否自动生成回复草稿 | | --reply_template | string | 内置模板 | 回复模板,支持 {name}, {interest}, {product} 变量 |

使用示例

场景 1: 每日扫描 AI 群聊

bash
# crontab 或 OpenClaw cron
openclaw cron add \
  --name "每日 AI 群聊线索扫描" \
  --schedule "0 9 * * *" \
  --payload.agentTurn.message "用 wechat-lead-generation 抓取 groups 中最近 1 天的 AI 相关对话,生成报告" \
  --delivery.announce.channel openclaw-weixin

场景 2: 分析好友咨询(半自动)

bash
# 先抓取分析,不自动回复
.agents/skills/wechat-lead-generation/bin/run \
  --source friends \
  --days_back 2 \
  --analysis_depth deep

# 人工审核报告后,对高评分线索单独发送回复

📊 输出报告结构

text
out

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 204)May include surrounding context.

清空输出目录

bash
rm -rf output/wechat-lead-generation/*

🔄 Roadmap

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is explicitly designed to collect WeChat conversation data, analyze it for lead generation, and retain it in reports, artifacts, and memory. In this context, the combination of private messaging content, profiling, scoring, and retention materially increases surveillance and privacy risk, especially if used on contacts who did not consent to this secondary processing.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The report generator embeds excerpts of private message content and names into a shareable Markdown report. This makes sensitive conversations portable and easy to redistribute outside the original chat environment, increasing the likelihood of unauthorized disclosure or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code writes customer profiles, high-scoring leads, and raw messages to local disk under a fixed workspace path, with no consent, notice, redaction, or access control. Because the data includes names and conversation excerpts from WeChat, this creates a clear privacy exposure and raises risk of unauthorized local access, accidental sharing, or policy noncompliance.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill sends lead information into an external memory layer without explicit disclosure, even though that information includes names, interests, scores, and summarized chat content. External or long-term memory use increases the chance of later reuse, leakage, or cross-context exposure of personal data beyond the original lead-generation task.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The memory storage logic persists identities and summarized chat content for future reuse, turning transient conversation analysis into long-term profiling. This broadens impact from a one-time lead report to ongoing retention and possible reuse in unrelated contexts, which is especially risky for personal communications data.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The artifacts export writes all profiles, high-scoring leads, and raw messages to disk, including original conversation data. Persisting full raw messages and associated profiles creates a concentrated local repository of sensitive communications that could be accessed by other processes, users, backups, or later operators.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The changelog explicitly advertises WeChat multi-channel data collection and historical storage, including friends, group chats, Moments, and public accounts, without any mention of consent, lawful basis, data minimization, retention limits, or protection of sensitive personal data. In a lead-generation skill, this omission increases the risk that operators will deploy privacy-invasive collection and persistence workflows that violate platform rules or privacy obligations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The publishing guide is written as a directive in Chinese and provides no indication that users may choose another language or that the skill is restricted to a Chinese-speaking audience for a documented reason. This creates a natural-language locale policy concern because it effectively forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is presented entirely in Chinese from the opening tagline onward, with no indication that language choice is optional or that the skill is region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs users to set a WECHAT_COOKIE environment variable for real data scraping but does not include any credential-handling, storage, rotation, or redaction guidance. Because a WeChat cookie is effectively an authenticated session token, accidental exposure through shell history, process listings, logs, screenshots, or shared terminal sessions could allow account takeover or unauthorized access to message data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill describes capabilities that imply network access and file output, but it does not declare any explicit tool scope, permissions, or allowed-tools boundaries. In an agent environment, this creates a least-privilege failure: the skill can be invoked without clear constraints on what tools it may use for scraping, storage, and report generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is explicitly designed to scrape WeChat friends, groups, moments, and articles, analyze conversation content for intent, and persist profiles in memory, yet the privacy discussion is limited to platform-terms and account-ban risk rather than informed consent, data minimization, or lawful basis for processing. This makes unauthorized collection, profiling, and retention of personal communications more likely, increasing the risk of privacy violations, sensitive-data exposure, and noncompliant surveillance/marketing use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language strings, logs, report content, and generated replies are predominantly fixed in Chinese, and the default reply/report behavior does not offer locale selection or user opt-in. This can violate language or locale policy where skills must not force a language without giving the user a choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill’s stated function is lead capture, analysis, and reply generation, but it also persists lead records into a separate long-term memory system. That expands data retention and downstream reuse of sensitive WeChat conversation content and identities beyond the core workflow, creating privacy and compliance risk if operators or users were not explicitly informed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language content for core feature descriptions is presented in Chinese only, which can amount to a language policy issue if users are not given a choice or the restriction is not justified. No opt-in, bilingual support, or region-specific rationale is provided in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file uses Chinese for nearly all contributor instructions, which effectively forces a specific language for participation. Under the policy rule, locale or language constraints should either be optional, user-selectable, or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.