Back to skill

Security audit

wechat-archive-to-ima

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated WeChat attachment-archiving purpose, but it needs review because its default workflow can move original files and it handles private chat attachments, decryption material, and cloud upload metadata without strong consent gates.

Install only if you are comfortable granting the skill access to local WeChat attachment folders you own or are authorized to process. Use --copy unless you explicitly intend to remove originals from WeChat-managed storage, keep secret_hit.json local and out of synced/shared folders, review files before any ima upload, and rotate the ima API key after use. Do not rely on the bundled ima uploader as a complete backup until its missing COS upload step is implemented and verified.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/organize_attachments.py:163
Finding

Attachment organizer destructively moves source files without enforced confirmation

Content
View full analysis

Vulnerability Details

File Location: scripts/organize_attachments.py:163-164, 274-278
Related Documentation: SKILL.md:165-176, 196
Vulnerability Type: Destructive source mutation without an enforced confirmation or dry-run gate
Risk Level: Medium

Vulnerable Code

python
ap.add_argument("--copy", action="store_true", help="复制(默认移动)")
python
# 落盘:解密件直接写字节,原文件按 --copy 复制/默认移动
if data is not None:
    try:
        target.write_bytes(data)
    except OSError as exc:
        print(f"[!] 写入失败 {target}: {exc}")
        continue
elif args.copy:
    shutil.copy2(fp, target)
else:
    shutil.move(str(fp), str(target))

The documented invocation omits --copy:

bash
python scripts/organize_attachments.py \
  --src "$ACCOUNT/$SRC" \
  --dst "<输出目录>/$SRC" \
  --contact "$SRC"

The documentation also states both that files are moved by default and that the source is read-only:

markdown
- 默认移动文件,预览/试跑请加 `--copy`
markdown
- 源目录只读,解密产物只写 `--out` / `--dst`

Technical Analysis

The --copy option is opt-in, so the default execution path calls shutil.move() for every matching plaintext attachment discovered recursively under --src. There is no interactive prompt, explicit confirmation parameter, dry-run requirement, or transaction-like rollback mechanism before source files are removed from their original locations.

This behavior is particularly risky because the Skill's documented workflow invokes the script without --copy and separately claims that the source directory is read-only. An agent following the documented command can therefore interpret the operation as nondestructive while the implementation relocates files from WeChat-managed storage.

This is a real, reachable unsafe default rather than evidence of a backdoor or malicious intent.

Attack Path

  1. A user asks the Skill to organize or archive locally downloaded WeChat attachments.
  2. The agent follows the command documented in ` ...[truncated 1275 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make copying the default behavior and require an explicit option such as --move for source mutation.
  2. Require a second explicit acknowledgement for destructive operation, such as:
    bash
    --move --confirm-source-removal
    
  3. Add a dry-run mode that lists every planned source and destination path without changing files.
  4. Before moving, display the normalized source and destination roots, the number of affected files, and the total data size.
  5. Reject overlapping source and destination directories to prevent recursive or inconsistent processing.
  6. Prefer a two-phase workflow: copy and verify hashes first, then remove source files only after successful verification and explicit confirmation.
  7. Handle partial failures with a manifest that supports rollback or safe resumption.
  8. Update SKILL.md so its read-only claims match the executable behavior. The standard documented command should include --copy unless the user explicitly requests source removal.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared scope emphasizes broad attachment archiving and downstream knowledge-base workflows, while the actual implemented capability appears narrower and more focused on .dat decryption internals. This mismatch is dangerous because it can hide the most sensitive function—low-level decryption/code recovery—behind a benign-sounding archival description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared scope emphasizes broad attachment archiving and downstream knowledge-base workflows, while the actual implemented capability appears narrower and more focused on .dat decryption internals. This mismatch is dangerous because it can hide the most sensitive function—low-level decryption/code recovery—behind a benign-sounding archival description.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
`scripts/wechat_dat_decrypt.py` 自动探测 .dat → 尾字节反推 xor → 枚举 wxid 候选

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
`scripts/wechat_dat_decrypt.py` 自动探测 .dat → 尾字节反推 xor → 枚举 wxid 候选

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

md
`scripts/wechat_dat_decrypt.py` 自动探测 .dat → 尾字节反推 xor → 枚举 wxid 候选

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes capabilities that read local files, write reorganized outputs, and upload content over the network, but it does not declare any explicit tool scope or permissions boundaries. That omission increases the chance an agent runtime grants broader-than-necessary access or that users are not adequately warned about sensitive filesystem and network operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that file organization moves files by default, which is a destructive operation that can alter or remove the user's original WeChat attachment layout. Without prominent upfront warning and safer defaults, an agent could unintentionally disrupt evidence, break user expectations, or cause data loss if the reorganization is interrupted or mis-targeted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs uploading locally archived chat attachments to Tencent ima using API credentials but does not prominently warn that private chat-derived files will be transmitted to a third-party cloud service. This creates a material privacy and compliance risk, especially because the files may contain contracts, invoices, personal images, or other sensitive content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document normalizes recursive access to local WeChat attachment directories and direct Markdown writes to an Obsidian vault, but it does not pair those actions with any explicit requirement for informed user consent, path confirmation, scope limitation, or preview-before-write safeguards. Because these files may contain sensitive personal or business data, an agent implementing this guidance could silently collect, reorganize, or overwrite private content in ways the user did not fully anticipate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document describes uploading archived materials to the external Tencent ima knowledge base via API, but it does not prominently warn that file contents, filenames, metadata, and possibly contact-linked context will leave the local machine and be transmitted to a third party. In this skill context, the data source is WeChat attachments, which often contain highly sensitive personal, financial, or contractual material, so omission of a clear transmission warning materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/ima_api.md (reported line 125)May include surrounding context.


5. 调用示例(curl 伪代码)

bash
# Step 1

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document provides concrete local WeChat storage paths and operational guidance for decrypting .dat attachments, but does not pair this with an explicit privacy/consent warning or handling restrictions. In this skill’s context, that materially lowers the barrier to bulk access and organization of personal chat attachments, which can enable unauthorized collection or overbroad processing of sensitive user data even if it avoids encrypted message databases.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script does more than detect WeChat paths: when run with --rank-contacts it recursively enumerates local attachment/file directories, derives contact identifiers, and ranks them by activity. That exposes relationship metadata and local communication patterns for all discovered accounts on the machine, which is privacy-sensitive and exceeds the narrow expectation implied by simple environment detection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code enumerates and ranks WeChat contact-related local data without any explicit warning that it will scan all account directories and reveal contact IDs, activity levels, timestamps, and aggregate sizes. Even though it does not decrypt databases, this metadata can still disclose sensitive social graph and usage information if run on a shared or managed machine.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring presents this as a working bulk uploader to 腾讯 ima, but the implementation only calls create_media and add_knowledge. Lines L068-L072 and L136-L137 explicitly show that the required COS multipart file upload is only a placeholder, so the behavior does not match the claimed end-to-end upload functionality.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function can return success after only creating remote metadata and calling add_knowledge, even though the file content was never uploaded. In this skill's context—archiving user files to a knowledge base—that can mislead users into believing sensitive records were backed up when they were not, creating integrity and data-loss risk during incident recovery or records retention workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script sends local file metadata such as file names, sizes, extensions, MIME types, and target knowledge base identifiers to a remote API without an explicit upfront privacy warning or confirmation step. In this skill's context, file names may reveal highly sensitive business or personal information (for example contracts, invoices, or customer names), so metadata disclosure alone can create a meaningful privacy leak even before content upload is implemented.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script defaults to moving files unless --copy is explicitly provided, which can delete the user's original WeChat attachments from their source tree during a routine archive operation. In this skill context, users are trying to organize local evidence and records, so destructive default behavior creates a real risk of accidental data loss and can interfere with later verification or reprocessing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code invokes brute-force derivation of decryption parameters for WeChat .dat files, which goes beyond simple format conversion and expands the tool into credential/secret recovery behavior. Even though this targets local files, the skill metadata explicitly frames boundaries around limited handling, so automatic key/code recovery increases abuse potential and may process protected data in ways the user did not fully understand.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script writes recovered decryption parameters (code, wxid, xor) into secret_hit.json under the output directory, creating a new at-rest secret artifact alongside decrypted attachment metadata. In this context, the output directory may be synced to knowledge bases, backups, or shared folders, so persisting secret material broadens exposure beyond the original local processing task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

At the point where files are copied or moved, the script performs a destructive move by default with no interactive warning, confirmation, or dry-run output. This is dangerous because a user invoking an 'archive' workflow may reasonably expect non-destructive behavior, and the mismatch can silently remove originals from the WeChat storage location.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, language constraints should be opt-in or explicitly justified; here no such choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language instructions and user-facing CLI help are all in Chinese, which imposes a specific language on users without indicating any choice or locale limitation. Under the stated policy, forcing a language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code creates or overwrites 'upload_failed.csv' inside the user-supplied source directory, which is a local file write affecting user data. Although the path is printed afterward, there is no prior warning in the docstring, comments, or initial output that running the script will create this additional file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.