Back to skill

Security audit

Windows WeChat MCP

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do what it claims, but it can send real WeChat messages and capture chat windows without strong safeguards.

Install only if you are comfortable letting an agent control your desktop WeChat session. Treat every send action as a real message from your account, keep WeChat in view, avoid ambiguous contact names, and do not use it for sensitive chats unless you add confirmation, recipient verification, clipboard restoration, and screenshot handling controls.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Third-Party Dependencies Allow Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:11-15; also documented in scripts/server.py:10-11
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code Snippet:

markdown
2. Python dependencies installed:
   ```bash
   pip install pyautogui pygetwindow pillow pyperclip opencv-python
   ```

The same installation instruction is also present in the script documentation:

python
Dependencies:
    pip install pyautogui pygetwindow pillow pyperclip opencv-python

Technical Analysis

The installation command specifies package names without exact versions or package hashes. Consequently, installation resolves whichever releases are available from the configured Python package index at that time.

This prevents reproducible dependency resolution and means the code reviewed during this audit may not be the code installed by a future user. If an upstream package account, release pipeline, or configured package index is compromised, a malicious release could execute code during package installation or when imported by scripts/server.py.

The project also imports these dependencies at module initialization, including pyautogui, pygetwindow, PIL, pyperclip, cv2, and numpy. A compromised dependency could therefore execute before any Skill function is called.

Attack Path

  1. An attacker compromises a listed package, its maintainer account, release infrastructure, or a package index trusted by the victim.
  2. The attacker publishes a malicious version under one of the dependency names.
  3. A user follows the documented unpinned pip install command.
  4. The package manager resolves and installs the malicious release because no approved version or hash is enforced.
  5. Malicious code executes during installation or when scripts/server.py imports the dependency.

Impact Assessment

Successful exploitation would run code with the pr ...[truncated 474 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed exact version, for example with package==version.
  2. Generate a lockfile containing all transitive dependency versions.
  3. Require package hashes during installation, such as through a hash-locked requirements file and pip install --require-hashes.
  4. Install packages only from an explicitly configured, trusted package index.
  5. Add automated dependency vulnerability and provenance scanning to the release process.
  6. Periodically update dependencies through a controlled review process rather than resolving mutable latest versions during installation.
  7. Move installation requirements into a version-controlled dependency manifest instead of relying solely on documentation commands.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/server.py:97
Finding

Message Sending Does Not Verify the Selected Recipient

Content
View full analysis

Vulnerability Details

File Location: scripts/server.py:97-113 and scripts/server.py:141-154
Vulnerability Type: Unsafe GUI automation and missing recipient verification
Risk Level: Medium

Vulnerable Code Snippet:

python
def search_contact(contact_name):
    """
    Search for and open a contact's chat window

    Args:
        contact_name: Contact name

    Returns:
        bool: Whether the contact was successfully found and opened
    """
    wechat = find_wechat_window()
    if not wechat:
        raise Exception("WeChat window not found")

    wechat.activate()
    time.sleep(0.3)

    # Use Ctrl+F to open search
    pyautogui.hotkey('ctrl', 'f')
    time.sleep(0.3)

    # Type the contact name
    pyperclip.copy(contact_name)
    pyautogui.hotkey('ctrl', 'v')
    time.sleep(0.5)

    # Press Enter to open the first search result
    pyautogui.press('enter')
    time.sleep(0.3)

    return True
python
def send_message_to_contact(contact_name, message):
    """
    Send a message to a specified contact (complete workflow)

    Args:
        contact_name: Contact name
        message: Message content
    """
    # Search for and open the contact
    search_contact(contact_name)

    # Send the message
    send_message_to_current(message)

The called message-sending function performs the irreversible action without checking the current conversation:

python
# Use clipboard to input the message (supports Chinese characters)
pyperclip.copy(message)
pyautogui.hotkey('ctrl', 'v')
time.sleep(0.1)

# Send the message
pyautogui.press('enter')

Technical Analysis

search_contact() enters the supplied contact name and immediately opens the first search result. It does not confirm that the result is an exact match, that any result exists, or that the resulting conversation belongs to the requested recipient. Des ...[truncated 1988 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require an exact and unique recipient match rather than opening the first search result.
  2. Inspect the selected conversation header through a reliable accessibility API, UI Automation interface, or carefully validated OCR before sending.
  3. Fail closed if no result, multiple results, an unexpected window, or a mismatched recipient is detected.
  4. Replace fixed sleep intervals with bounded waits that test explicit window and control states.
  5. Revalidate the foreground window, focused input control, and displayed recipient immediately before pasting and again before pressing Enter.
  6. Make search_contact() return a verified recipient identity or a meaningful failure result; ensure callers stop when verification fails.
  7. Require explicit user confirmation for ambiguous recipients or messages classified as sensitive.
  8. Clear or restore clipboard contents after sending to reduce residual exposure.
  9. Add error handling and audit logging that records the requested recipient, verified recipient, and send outcome without logging confidential message content.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: windows-wechat-mcp
description: Windows WeChat message monitoring and sending. Achieved through window automation: screenshot, search contacts, send messages. Use when needing to send messages to WeChat contacts, check WeChat window status, or perform WeChat-related automation tasks.
---

# Windows WeChat MCP

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
Features:
- Capture screenshots of the WeChat window
- Search for and open contact chat windows
- Send messages to specified contacts
- Support identification of and message sending to detached chat windows

Dependencies:

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · scripts/server.py (reported line 7)May include surrounding context.

python
Features:
- Capture screenshots of the WeChat window
- Search for and open contact chat windows
- Send messages to specified contacts
- Support identification of and message sending to detached chat windows

Dependencies:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly documents automating WeChat actions on the user's behalf, including searching contacts, opening chats, and sending messages, but it does not include a clear warning that the agent may perform real external actions in the user's messaging account. In a messaging context, this can lead to unintended communications, privacy incidents, or social-engineering amplification if invoked without strong user awareness and confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function programmatically captures the WeChat window and can optionally persist chat screenshots to disk without any consent, visibility, or access control. Because the content consists of private chat data, this creates a clear confidentiality risk and could enable silent collection or later exfiltration of sensitive conversations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code uses GUI automation and the system clipboard to search contacts and send messages, which can overwrite clipboard contents and trigger outbound messages without any user approval or verification of the intended recipient. In a messaging client context, this can directly cause unauthorized message transmission, privacy loss, and social-engineering abuse from the victim's own account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The notes state that the WeChat window is automatically activated during message sending, but there is no warning about UI automation side effects such as focus stealing, interference with other applications, or accidental interaction with the wrong window. Because this operates through desktop automation, lack of warning increases the risk of misdirected input and unintended actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.