Back to skill

Security audit

WeChat Lead Generation

Security checks across malware telemetry and agentic risk

Overview

This skill openly targets WeChat lead scraping and marketing follow-up, but it retains identifiable chat-derived data in files and agent memory with weak consent, retention, and user-control safeguards.

Install only after a privacy and compliance review. Do not connect a real WeChat cookie or enable scheduled scanning unless you have authorization to process the affected conversations. Keep auto-reply disabled, avoid storing raw messages or names where possible, and plan how to restrict access, delete outputs, and clear agentmemory entries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill persists extracted lead information into long-term agent memory, expanding data retention beyond the core scrape/analyze/report flow. Because the stored records include names, message excerpts, interests, and scores from private WeChat interactions, this creates unnecessary secondary use and retention of personal data without clear consent or disclosure.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill is explicitly designed for large-scale scraping of WeChat friends, groups, moments, and articles, followed by analysis and long-term storage of lead data, without a clear consent model or strong privacy notice. This creates substantial privacy and compliance risk because private communications and contact data may be collected and profiled without the knowledge or permission of the affected individuals.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill writes sensitive conversation content, names, profiles, and lead scores to local files in reports and artifacts without any visible consent, notice, or access-control safeguards. Persisting raw WeChat-derived data in plaintext materially increases the risk of privacy breach, unauthorized access, and unintended downstream use.

Missing User Warnings

High
Confidence
97% confidence
Finding
Customer lead data is exported into external memory storage without clear disclosure or consent, creating a second persistence channel outside the generated report files. This broadens exposure, weakens data minimization, and may violate privacy expectations or policy obligations for private messaging data.

Ssd 3

Medium
Confidence
95% confidence
Finding
The README explicitly instructs storing sensitive artifacts such as raw private messages, customer profiles, and high-score lead lists on disk. In the context of a tool that scrapes WeChat conversations, this creates a real privacy and data-exposure risk because highly sensitive, identity-linked communications may be retained in plaintext reports and artifacts that can be accessed, exfiltrated, or mishandled.

Ssd 3

Medium
Confidence
94% confidence
Finding
The example report normalizes inclusion of named individuals, inferred interests, purchase intent, and verbatim message excerpts in generated output. That is dangerous because it encourages operators to produce sharable reports containing personal data and private conversation content, increasing the likelihood of privacy violations, insider leakage, and unauthorized downstream use.

Ssd 3

High
Confidence
99% confidence
Finding
These instructions plainly describe collecting private WeChat conversations, analyzing intent, generating customer profiles, and storing leads for follow-up marketing. In this context, the skill is more dangerous because it targets personal communications for surveillance-like profiling and commercial use, which can expose sensitive personal data and enable unauthorized targeting.

Ssd 3

High
Confidence
99% confidence
Finding
The output artifacts include raw messages, profiles, and persistent lead data derived from scraped conversations, which materially increases privacy risk and breach impact. Storing raw captured messages and inferred profiles creates a rich, linkable dataset that could be misused internally or exposed if the environment is compromised.

Ssd 3

High
Confidence
98% confidence
Finding
The scheduled task automates daily scanning of group chats for lead extraction based on message content, turning sensitive monitoring into a continuous background process. Automation at this cadence increases scale and stealth, making unauthorized surveillance, mass profiling, and policy violations more likely.

Ssd 3

High
Confidence
99% confidence
Finding
Documenting an output file containing original captured messages indicates deliberate retention of raw private communications. This is especially dangerous in a lead-generation skill because the raw content may contain sensitive personal, business, or confidential information beyond what is needed for legitimate reporting.

Ssd 3

High
Confidence
99% confidence
Finding
The skill’s stated workflow explicitly centers on collecting, analyzing, scoring, and persisting private WeChat content and identities, then generating reports and storing leads in memory. In this context, the danger is elevated because the data source is private interpersonal communications, making unauthorized retention, profiling, and exposure especially sensitive.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.