Back to skill

Security audit

Yq Weixin Connect

Security checks for vulnerabilities and agentic risk

Overview

This skill is for connecting personal WeChat, but it asks the agent to install and replace persistent code, store account credentials, and follow unsafe mandatory command instructions.

Review this before installing. It may replace an existing OpenClaw WeChat extension, run npm-installed code, store your WeChat connector token locally, upload the QR image through a CDN flow, and restart the gateway. Only proceed if you trust the package source and are comfortable managing the persisted credential and extension state.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:24
Finding

Mandatory Workflow Instructions Override Agent Safety and Autonomy

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:44
Finding

Mutable and Unpinned npm Dependencies Permit Supply-Chain Code Execution

Content
View full analysis
&1 | tail -1 && rm -rf ~/.openclaw/extensions/openclaw-weixin && mkdir -p ~/.openclaw/extensions/openclaw-weixin && tar -xzf /tmp/tencent-weixin-openclaw-weixin-*.tgz -C ~/.openclaw/extensions/openclaw-weixin --strip-components=1 && cd ~/.openclaw/extensions/openclaw-weixin && npm install --production 2>&1 | tail -3 && (ln -sf "$(npm root -g)/openclaw" node_modules/openclaw 2>/dev/null || ln -sf "$(dirname "$(which openclaw)")/../lib/node_modules/openclaw" node_modules/openclaw) && ls node_modules/openclaw/package.json >/dev/null 2>&1 && echo "READY" || echo "FAILED" ``` ```bash cd /tmp && npm install qrcode 2>/dev/null | tail -1 ``` ### Technical Analysis The extension is resolved through the mutable npm tag `legacy`, while `qrcode` is installed without an exact version. Neither operation verifies an expected integrity hash or immutable package artifact. The extension subsequently runs `npm install --production`, which may retrieve additional dependencies according to package metadata. npm installations can execute lifecycle scripts unless explicitly disabled. Therefore, a compromised package, mutable tag, dependency release, or registry response can introduce executable code after the Skill has been reviewed. The command also immediately replaces the existing extension before performing complete provenance or behavior validation. As a result, package resolution is part of the trusted execution path even though the resolved code is not present in the audited project. ### Attack Path 1. An attacker compromises the npm account, registry distribution channel, mutable `legacy` tag, unpinned `qrcode` release, or a transitive production dependency. 2. The Agent invokes `npm pack` or `npm install` ...[truncated 1040 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:157
Finding

Unescaped Remote Authentication Values Are Embedded in Executable JavaScript

Content
View full analysis
/tmp/write_weixin_account.js << 'SCRIPT' const fs = require('fs'); const path = require('path'); const home = process.env.HOME; const accountId = ''; const data = { token: '', savedAt: new Date().toISOString(), baseUrl: '', userId: '' }; const accountsDir = path.join(home, '.openclaw/openclaw-weixin/accounts'); fs.mkdirSync(accountsDir, { recursive: true }); const accountFile = path.join(accountsDir, accountId + '.json'); fs.writeFileSync(accountFile, JSON.stringify(data, null, 2)); fs.chmodSync(accountFile, 0o600); const indexPath = path.join(home, '.openclaw/openclaw-weixin/accounts.json'); let existing = []; try { existing = JSON.parse(fs.readFileSync(indexPath, 'utf-8')); } catch {} if (!existing.includes(accountId)) existing.push(accountId); fs.writeFileSync(indexPath, JSON.stringify(existing, null, 2)); console.log('Credential and index write completed'); SCRIPT node /tmp/write_weixin_account.js ``` The Skill directs the placeholders to be replaced inline with values returned by the remote QR-code status API. ### Technical Analysis The values `accountId`, `bot_token`, `baseurl`, and `ilink_user_id` are inserted directly into JavaScript single-quoted string literals. The documented procedure does not apply JSON encoding, JavaScript escaping, schema validation, or strict character allowlists before generating and executing the script. If an inserted value contains a single quote, backslash, line terminator, or JavaScript syntax, it can terminate the intended string and inject statements into `/tmp/write_weixin_account.js`. Running the generated file with Node.js then converts a remote data response into a code-execution channel. The temporary script also contains the pla ...[truncated 2051 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
---
AIGC:
    ContentProducer: Minimax Agent AI
    ContentPropagator: Minimax Agent AI
    Label: AIGC
    ProduceID: 8652358b4ffabd0bcdab478baa03b691
    PropagateID: 8652358b4ffabd0bcdab478baa03b691
    ReservedCode1: 3045022066f0177a83396e1fdb740c805c1a818a1536243f3983c7d21bcf93fee2c23ef40221008076ebf6da639ad539fe58e60ca22edf5f788223e0194452d6d8966d4d91dd6c
    ReservedCode2: 3046022100a568592c565991ecd9b401fd64c1bf5bb96b4932b90aaf207180424a360b39930221009b4319014a4378ad7097b6fadf54f0ecf3c5ea6a1f2bad07e08812312662cf29
description: 连接个人微信(不是企业微信)。用户说"连接个人微信"、"接入个人微信"、"绑定个人微信"、"个人微信扫码"时使用本 skill。注意:如果用户说的是"企业微信"或"企微",本 skill 不适用,请使用 wecom-connect skill。一�

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The skill directs use of rm -rf ~/.openclaw/extensions/openclaw-weixin as part of a chained install command. While scoped, it is still a destructive filesystem operation executed automatically, and if path handling or environment assumptions are wrong it can remove an existing trusted installation or enable downgrade/replacement with unverified code.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

直接安装兼容的 legacy 版本,不需要做版本检查:

bash
cd /tmp && npm pack @tencent-weixin/openclaw-weixin@legacy 2>&1 | tail -1 && rm -rf ~/.openclaw/extensions/openclaw-weixin && mkdir -p ~/.openclaw/extensions/openclaw-weixin && tar -xzf /tmp/tencent-weixin-openclaw-weixin-*.tgz -C ~/.openclaw/extensions/openclaw-weixin --strip-components=1 && cd ~/.openclaw/extensions/openclaw-weixin && npm install --production 2>&1 | tail -3 && (ln -sf "$(npm root -g)/openclaw" node_modules/openclaw 2>/dev/null || ln -sf "$(dirname "$(which openclaw)")/../lib/node_modules/openclaw" node_modules/openclaw) && ls node_modules/openclaw/package.json >/dev/null 2>&1 && echo "READY" || echo "FAILED"
  • READY → 继续第 2 步

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The skill directs use of rm -rf ~/.openclaw/extensions/openclaw-weixin as part of a chained install command. While scoped, it is still a destructive filesystem operation executed automatically, and if path handling or environment assumptions are wrong it can remove an existing trusted installation or enable downgrade/replacement with unverified code.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

直接安装兼容的 legacy 版本,不需要做版本检查:

bash
cd /tmp && npm pack @tencent-weixin/openclaw-weixin@legacy 2>&1 | tail -1 && rm -rf ~/.openclaw/extensions/openclaw-weixin && mkdir -p ~/.openclaw/extensions/openclaw-weixin && tar -xzf /tmp/tencent-weixin-openclaw-weixin-*.tgz -C ~/.openclaw/extensions/openclaw-weixin --strip-components=1 && cd ~/.openclaw/extensions/openclaw-weixin && npm install --production 2>&1 | tail -3 && (ln -sf "$(npm root -g)/openclaw" node_modules/openclaw 2>/dev/null || ln -sf "$(dirname "$(which openclaw)")/../lib/node_modules/openclaw" node_modules/openclaw) && ls node_modules/openclaw/package.json >/dev/null 2>&1 && echo "READY" || echo "FAILED"
  • READY → 继续第 2 步

Chaining Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The skill explicitly insists on combining many sensitive actions into a single &&-chained exec call for speed, including package fetch, deletion of an existing extension, extraction, dependency install, symlink creation, and readiness checks. This reduces observability and user review, making it easier for destructive or unsafe subcommands to execute atomically and harder to interrupt or audit partial failure states.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

直接安装兼容的 legacy 版本,不需要做版本检查:

bash
cd /tmp && npm pack @tencent-weixin/openclaw-weixin@legacy 2>&1 | tail -1 && rm -rf ~/.openclaw/extensions/openclaw-weixin && mkdir -p ~/.openclaw/extensions/openclaw-weixin && tar -xzf /tmp/tencent-weixin-openclaw-weixin-*.tgz -C ~/.openclaw/extensions/openclaw-weixin --strip-components=1 && cd ~/.openclaw/extensions/openclaw-weixin && npm install --production 2>&1 | tail -3 && (ln -sf "$(npm root -g)/openclaw" node_modules/openclaw 2>/dev/null || ln -sf "$(dirname "$(which openclaw)")/../lib/node_modules/openclaw" node_modules/openclaw) && ls node_modules/openclaw/package.json >/dev/null 2>&1 && echo "READY" || echo "FAILED"
  • READY → 继续第 2 步

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The skill installs a plugin into the user's home directory (~/.openclaw/extensions/...), creating persistent state that survives the current session. Persistent installation is not inherently malicious, but in this context it modifies the agent runtime and leaves behind executable code and account material without emphasizing trust verification, rollback, or cleanup.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

直接安装兼容的 legacy 版本,不需要做版本检查:

bash
cd /tmp && npm pack @tencent-weixin/openclaw-weixin@legacy 2>&1 | tail -1 && rm -rf ~/.openclaw/extensions/openclaw-weixin && mkdir -p ~/.openclaw/extensions/openclaw-weixin && tar -xzf /tmp/tencent-weixin-openclaw-weixin-*.tgz -C ~/.openclaw/extensions/openclaw-weixin --strip-components=1 && cd ~/.openclaw/extensions/openclaw-weixin && npm install --production 2>&1 | tail -3 && (ln -sf "$(npm root -g)/openclaw" node_modules/openclaw 2>/dev/null || ln -sf "$(dirname "$(which openclaw)")/../lib/node_modules/openclaw" node_modules/openclaw) && ls node_modules/openclaw/package.json >/dev/null 2>&1 && echo "READY" || echo "FAILED"
  • READY → 继续第 2 步

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to persist live authentication material (bot_token, baseurl, ilink_user_id) into local files under ~/.openclaw/... without any user consent prompt, retention guidance, or warning that long-lived credentials are being stored. Even though the file mode is set to 0600, this still creates a recoverable secret on disk that may be exposed through backup systems, later compromise of the host account, or other local tooling.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
SKILL.md:44