Back to skill

Security audit

mmxagent-skill-wechat

Security checks for vulnerabilities and agentic risk

Overview

The skill is meant to connect personal WeChat, but it gives broad install, credential, and gateway-changing instructions with unsafe scoping and execution patterns.

Review before installing. Use this only if you trust the npm packages, registry mirror, Tencent WeChat endpoints, and OpenClaw gateway changes. Prefer a revised version that pins package versions, preserves normal agent discretion, keeps QR codes local by default, validates API responses, writes credentials through data-only JSON handling, and asks clearly before global installs or persistent token writes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:18
Finding

Skill Instructions Override Agent Safety and Decision-Making

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:45
Finding

Unpinned Runtime Installation and Execution of Third-Party Packages

Content
View full analysis
&1 ``` ```bash npm install -g openclaw@latest --registry=https://registry.npmmirror.com 2>&1 | tail -3 ``` ```bash npx -y @tencent-weixin/openclaw-weixin-cli@latest install 2>&1 ``` ```bash npm install -g openclaw@latest --registry=https://registry.npmmirror.com 2>&1 | tail -3 ``` ```bash cd /tmp && npm install qrcode 2>/dev/null | tail -1 ``` ### Technical Analysis The Skill downloads and executes packages at runtime without pinning immutable versions or verifying package integrity. The use of `@latest` means that the reviewed Skill does not determine which package code will execute when invoked. `npx -y` is particularly sensitive because it automatically downloads and executes the selected package without an interactive confirmation. npm package installation can also execute package lifecycle scripts. The global OpenClaw installation modifies the user's global toolchain and retrieves code through a configured mirror, increasing the number of supply-chain trust dependencies. Suppressing most installation output with `tail` and redirecting errors to `/dev/null` also makes integrity and installation problems harder to detect. ### Attack Path 1. An attacker compromises a package publisher account, package release, registry, mirror, or dependency. 2. A malicious release becomes the package resolved by `@latest`, or an unpinned transitive dependency is altered. 3. The Skill invokes `npx` or `npm install`. 4. Malicious CLI code or lifecycle scripts execute with the privileges of the agent process. 5. The malicious code reads local data, modifies installed tools, steals credentials, or establishes additional comprom ...[truncated 600 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:122
Finding

Remote QR Content Is Interpolated into an Executable Node Command

Content
View full analysis
',{width:400,margin:2},(e)=>{if(e)console.error(e);else console.log('saved');})" ``` The `` placeholder is replaced with data returned by the remote QR-code API. ### Technical Analysis Remote `qrcode_img_content` is inserted directly into JavaScript source passed through a shell command. It is therefore interpreted in two executable contexts: 1. The shell parses the outer double-quoted command. 2. Node parses the resulting JavaScript source. A malicious value containing quotes, backslashes, shell substitutions, or JavaScript syntax can escape the intended string literal. For example, a crafted response can terminate the JavaScript string and append additional JavaScript statements. Shell-sensitive constructs may also be evaluated while the double-quoted `node -e` argument is assembled. The instructions do not require schema validation, character validation, safe argument transport, or origin verification beyond the fixed API request. ### Attack Path 1. An attacker gains control over the QR API response, its delivery path, or an upstream service that supplies `qrcode_img_content`. 2. The response contains a crafted value that closes the single-quoted JavaScript string or introduces shell-sensitive syntax. 3. The agent substitutes the value into the documented `node -e` command. 4. The shell and Node interpret the injected syntax. 5. Attacker-controlled code executes with the privileges of the agent process. ### Impact Assessment Exploitation permits arbitrary user-level code execution. The injected code could: - Read OpenClaw configuration and credential files. - Access environment variables and other user files. - Modify the g ...[truncated 232 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:226
Finding

Remote Credential Fields Are Inserted Directly into Generated JavaScript

Content
View full analysis
/tmp/write_weixin_account.js << 'SCRIPT' const fs = require('fs'); const path = require('path'); const home = process.env.HOME; const accountId = ''; const data = { token: '', savedAt: new Date().toISOString(), baseUrl: '', userId: '' }; const accountsDir = path.join(home, '.openclaw/openclaw-weixin/accounts'); fs.mkdirSync(accountsDir, { recursive: true }); const accountFile = path.join(accountsDir, accountId + '.json'); fs.writeFileSync(accountFile, JSON.stringify(data, null, 2)); fs.chmodSync(accountFile, 0o600); const indexPath = path.join(home, '.openclaw/openclaw-weixin/accounts.json'); let existing = []; try { existing = JSON.parse(fs.readFileSync(indexPath, 'utf-8')); } catch {} if (!existing.includes(accountId)) existing.push(accountId); fs.writeFileSync(indexPath, JSON.stringify(existing, null, 2)); console.log('凭证 + 索引写入成功'); SCRIPT node /tmp/write_weixin_account.js ``` The instructions require ``, ``, ``, and `` to be replaced with values derived from the remote API response. ### Technical Analysis The generated script treats remote credential fields as JavaScript source rather than data. No escaping is applied before the values are placed inside single-quoted string literals. An API value containing a single quote and valid JavaScript syntax can terminate its string and inject arbitrary statements. The resulting file is then immediately executed by Node. Displaying a masked token to the user does not mitigate this issue because the user does not review the complete generated source or full remote values. In addition, `accountId` is used to construct a filesystem path without an explicit allowlist. Although the documented transformation repl ...[truncated 1393 chars]
Remediation
View remediation

other

Warning
Location
SKILL.md:130
Finding

Optional CDN Upload Exposes a Live Authentication QR Code

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Defaulting a broad request like 连接微信 to personal WeChat can trigger the wrong skill when the user intent is ambiguous. In this skill, the consequence is not merely UX confusion: it initiates plugin installation, external network calls, QR-based authentication, and credential handling for a personal account, so accidental invocation can lead to unintended account binding or sensitive workflow execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill executes an unpinned package with npx ...@latest install, which fetches and runs whatever code is current in the registry at execution time. This creates a supply-chain risk: if the package is compromised, typo-squatted upstream, or a malicious update is published, the agent will execute attacker-controlled code on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This is the same unpinned runtime execution pattern in a second code path, again using npx ...@latest install. Because the skill is specifically designed to install and execute external tooling, the lack of version pinning materially increases the chance of arbitrary code execution through a compromised or unexpected package release.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill hardcodes user-facing instructions and expected confirmations in Chinese, such as asking the user to reply 'ok' after scanning. There is no indication that the user can choose another language or that the locale restriction is intentionally limited to a justified region-specific context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.