Back to skill

Security audit

wechat-chat-export-mac

Security checks for vulnerabilities and agentic risk

Overview

This is a powerful WeChat export and decryption workflow that is mostly upfront about its goal, but it needs Review because it handles private chat archives, decryption material, and desktop automation with weak scoping and confirmations.

Install only if you are exporting WeChat data you own or are clearly authorized to handle. Before running it, confirm the target account, contact/session hash, month, and destination directory; avoid running it on shared machines; treat CODE/WXID/derived keys and exported archives as confidential; remove or redact key-printing output; and do not upload the archive to AI knowledge bases unless the data owner has approved that transfer.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

In this variant, the mismatch is security-relevant because the skill presents itself as an export utility while also guiding filesystem enumeration of local WeChat storage, account identifiers, conversation hashes, and decryption parameters. When a skill touching private message archives understates or misstates its true behavior, users may authorize sensitive local-data reconnaissance they did not fully expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

In this variant, the mismatch is security-relevant because the skill presents itself as an export utility while also guiding filesystem enumeration of local WeChat storage, account identifiers, conversation hashes, and decryption parameters. When a skill touching private message archives understates or misstates its true behavior, users may authorize sensitive local-data reconnaissance they did not fully expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

In this variant, the mismatch is security-relevant because the skill presents itself as an export utility while also guiding filesystem enumeration of local WeChat storage, account identifiers, conversation hashes, and decryption parameters. When a skill touching private message archives understates or misstates its true behavior, users may authorize sensitive local-data reconnaissance they did not fully expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

In this variant, the mismatch is security-relevant because the skill presents itself as an export utility while also guiding filesystem enumeration of local WeChat storage, account identifiers, conversation hashes, and decryption parameters. When a skill touching private message archives understates or misstates its true behavior, users may authorize sensitive local-data reconnaissance they did not fully expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

In this variant, the mismatch is security-relevant because the skill presents itself as an export utility while also guiding filesystem enumeration of local WeChat storage, account identifiers, conversation hashes, and decryption parameters. When a skill touching private message archives understates or misstates its true behavior, users may authorize sensitive local-data reconnaissance they did not fully expect.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section frames a workflow for exporting a contact's files, images, and videos from WeChat, including sensitive categories such as contracts, financial records, and government documents. Even with anonymization language, it operationalizes bulk extraction of private communications content, which can enable unauthorized surveillance, privacy violations, and data theft.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These steps provide procedural guidance for sustained collection of chat artifacts through GUI automation, bulk retrieval, decryption, validation, and delivery. That turns the document into a practical playbook for harvesting private data at scale, lowering the barrier for misuse against any accessible account/session on the machine.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document chains parameter discovery, decryption, automated retrieval, completeness verification, packaging, and downstream import into a complete data acquisition pipeline. In context, this is more dangerous because the skill is specifically designed to extract and operationalize private WeChat media from local app storage, making misuse straightforward and scalable.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs use of filesystem reads, shell commands, AppleScript/UI automation, and decryption-related operations against local WeChat data, but it declares no explicit tool scope or permission boundaries. That makes the capability set opaque to the agent/runtime and increases the chance of over-broad execution against sensitive local data without informed consent or policy enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description says it should be used '当用户要把微信里某个联系人、某段时间的文件图片视频批量下载到本地时用', which is a broad intent description rather than a specific invocation scope. It does not define explicit trigger phrases, constraints, or negative examples, so the skill could be matched for many ordinary requests about downloading WeChat content.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/code-finding.md (reported line 25)May include surrounding context.

md
| `xwechat_files/<wxid>/config/`(login_config 等) | ❌ 加密 |
| `xwechat_files/all_users/config/` | ❌ 加密 |
| `xwechat_files/<wxid>/db_storage/`(SQLCipher) | ❌ 加密 |
| `Data/Library/Preferences/*.plist` | ❌ 没有 |
| `Library/Group Containers/5A4RE8SF68.com.tencent.xinWeChat` | ❌ 没有 |
| 整个 xwechat_files 全文 grep | ⏱ 超时(几十万 .dat),且命中 0 |

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section documents how to obtain a WeChat account-derived decryption code from Windows registry/config sources and also discusses Mac-side reverse engineering to recover equivalent secrets. That materially expands the skill from user-directed export into credential/secret extraction guidance that can be abused to decrypt private media from another device or account context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These instructions direct the operator to collect sensitive account identifiers from Windows registry/config locations without any warning that they are secrets tied to message/media decryption. Because the identifiers are reused to derive decryption material, exposing retrieval paths lowers the barrier to unauthorized access to private chat media.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation operationalizes validation and bulk decryption of WeChat .dat content and confirms successful recovery of original media formats, but provides no privacy, consent, or lawful-use guardrails. In this context, the skill is specifically built to mass export contact conversations and media, so omission of access-control and user-authorization constraints makes misuse against sensitive personal data substantially more dangerous.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The SOP extends beyond local export into uploading the collected archive to external AI knowledge bases, which increases data exposure and creates an unnecessary exfiltration path for highly sensitive chat-derived files. Because the exported materials include contracts, financial records, government documents, images, and videos, this step materially raises privacy, confidentiality, and compliance risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/wx_decrypt.py (reported line 44)May include surrounding context.

python
def transcode(wxgf_path, jpg_path):
    """wxgf = 微信裸 HEVC,必须 -f hevc"""
    r = subprocess.run(["ffmpeg", "-y", "-v", "error", "-f", "hevc",
                        "-i", wxgf_path, "-frames:v", "1", jpg_path],
                       capture_output=True, text=True, timeout=60)
    return r.returncode == 0

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script prints the derived decryption key and XOR byte in its JSON summary, even though exporting decrypted files does not require disclosing that material. This unnecessarily exposes reusable decryption material to terminal logs, shell history capture tools, CI logs, or any higher-level agent that records stdout, increasing the chance of unauthorized reuse or forensic leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Derived decryption material is emitted to standard output without warning, making secret exposure the default behavior. In this skill context, stdout is especially likely to be captured by automation, wrappers, transcripts, or user support artifacts, so the leak is more dangerous than in a purely local one-off script.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script automates WeChat GUI actions that cause bulk media downloads and requires powerful macOS Accessibility and Screen Recording permissions, yet it provides only technical usage notes and no explicit warning about side effects. In the wrong chat or month, it can trigger unintended export of large volumes of private data and create local data-handling risk without a deliberate confirmation step.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/wx_download.py (reported line 26)May include surrounding context.

python
def asy(s, timeout=25):
    r = subprocess.run(["osascript", "-e", s], capture_output=True, text=True, timeout=timeout)
    return (r.stdout + r.stderr).strip()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script enumerates local WeChat account directories and prints derived WXID values, session hashes, and message/video storage paths to stdout. Even though it is read-only, these identifiers and paths are sensitive metadata that can expose private account structure, facilitate later exfiltration/decryption steps, and leak into terminal history or logs. In this skill’s context, the script is explicitly part of a workflow to locate decryption parameters for bulk chat export, which makes the disclosure more security-sensitive than a generic diagnostic tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The display name is presented only in Chinese, and the document consistently assumes Chinese-language UI terms and interaction without indicating any language or locale choice. For a general-purpose skill, this can violate language-choice expectations unless the locale restriction is explicitly documented as user-facing policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The SOP is written entirely in Chinese and presents the workflow as the default operating mode, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the constraint is documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
68% confidence
Finding

The helper runs osascript commands to control another application, which is a form of subprocess execution with privileged desktop automation effects. Although this is central to the script's purpose, the code lacks an explicit disclosure near execution points that it will invoke AppleScript/System Events to manipulate WeChat.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This code file reads a .dat file and attempts full decryption, which can expose user data, but the script does not include a confirmation prompt or explicit warning comment/docstring about the sensitivity of decrypted output. Although the script's purpose implies decryption, there is still no direct user disclosure that the operation handles potentially sensitive local data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.