T01 · Skill Instruction Hijacking
- Location
SKILL.md:24- Finding
Mandatory Workflow Instructions Override Agent Safety and Autonomy
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is for connecting personal WeChat, but it asks the agent to install and replace persistent code, store account credentials, and follow unsafe mandatory command instructions.
Review this before installing. It may replace an existing OpenClaw WeChat extension, run npm-installed code, store your WeChat connector token locally, upload the QR image through a CDN flow, and restart the gateway. Only proceed if you trust the package source and are comfortable managing the persisted credential and extension state.
SKILL.md:24Mandatory Workflow Instructions Override Agent Safety and Autonomy
SKILL.md:44Mutable and Unpinned npm Dependencies Permit Supply-Chain Code Execution
SKILL.md:157Unescaped Remote Authentication Values Are Embedded in Executable JavaScript
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
AIGC:
ContentProducer: Minimax Agent AI
ContentPropagator: Minimax Agent AI
Label: AIGC
ProduceID: 8652358b4ffabd0bcdab478baa03b691
PropagateID: 8652358b4ffabd0bcdab478baa03b691
ReservedCode1: 3045022066f0177a83396e1fdb740c805c1a818a1536243f3983c7d21bcf93fee2c23ef40221008076ebf6da639ad539fe58e60ca22edf5f788223e0194452d6d8966d4d91dd6c
ReservedCode2: 3046022100a568592c565991ecd9b401fd64c1bf5bb96b4932b90aaf207180424a360b39930221009b4319014a4378ad7097b6fadf54f0ecf3c5ea6a1f2bad07e08812312662cf29
description: 连接个人微信(不是企业微信)。用户说"连接个人微信"、"接入个人微信"、"绑定个人微信"、"个人微信扫码"时使用本 skill。注意:如果用户说的是"企业微信"或"企微",本 skill 不适用,请使用 wecom-connect skill。一�
The skill directs use of rm -rf ~/.openclaw/extensions/openclaw-weixin as part of a chained install command. While scoped, it is still a destructive filesystem operation executed automatically, and if path handling or environment assumptions are wrong it can remove an existing trusted installation or enable downgrade/replacement with unverified code.
直接安装兼容的 legacy 版本,不需要做版本检查:
cd /tmp && npm pack @tencent-weixin/openclaw-weixin@legacy 2>&1 | tail -1 && rm -rf ~/.openclaw/extensions/openclaw-weixin && mkdir -p ~/.openclaw/extensions/openclaw-weixin && tar -xzf /tmp/tencent-weixin-openclaw-weixin-*.tgz -C ~/.openclaw/extensions/openclaw-weixin --strip-components=1 && cd ~/.openclaw/extensions/openclaw-weixin && npm install --production 2>&1 | tail -3 && (ln -sf "$(npm root -g)/openclaw" node_modules/openclaw 2>/dev/null || ln -sf "$(dirname "$(which openclaw)")/../lib/node_modules/openclaw" node_modules/openclaw) && ls node_modules/openclaw/package.json >/dev/null 2>&1 && echo "READY" || echo "FAILED"
READY → 继续第 2 步The skill directs use of rm -rf ~/.openclaw/extensions/openclaw-weixin as part of a chained install command. While scoped, it is still a destructive filesystem operation executed automatically, and if path handling or environment assumptions are wrong it can remove an existing trusted installation or enable downgrade/replacement with unverified code.
直接安装兼容的 legacy 版本,不需要做版本检查:
cd /tmp && npm pack @tencent-weixin/openclaw-weixin@legacy 2>&1 | tail -1 && rm -rf ~/.openclaw/extensions/openclaw-weixin && mkdir -p ~/.openclaw/extensions/openclaw-weixin && tar -xzf /tmp/tencent-weixin-openclaw-weixin-*.tgz -C ~/.openclaw/extensions/openclaw-weixin --strip-components=1 && cd ~/.openclaw/extensions/openclaw-weixin && npm install --production 2>&1 | tail -3 && (ln -sf "$(npm root -g)/openclaw" node_modules/openclaw 2>/dev/null || ln -sf "$(dirname "$(which openclaw)")/../lib/node_modules/openclaw" node_modules/openclaw) && ls node_modules/openclaw/package.json >/dev/null 2>&1 && echo "READY" || echo "FAILED"
READY → 继续第 2 步The skill explicitly insists on combining many sensitive actions into a single &&-chained exec call for speed, including package fetch, deletion of an existing extension, extraction, dependency install, symlink creation, and readiness checks. This reduces observability and user review, making it easier for destructive or unsafe subcommands to execute atomically and harder to interrupt or audit partial failure states.
直接安装兼容的 legacy 版本,不需要做版本检查:
cd /tmp && npm pack @tencent-weixin/openclaw-weixin@legacy 2>&1 | tail -1 && rm -rf ~/.openclaw/extensions/openclaw-weixin && mkdir -p ~/.openclaw/extensions/openclaw-weixin && tar -xzf /tmp/tencent-weixin-openclaw-weixin-*.tgz -C ~/.openclaw/extensions/openclaw-weixin --strip-components=1 && cd ~/.openclaw/extensions/openclaw-weixin && npm install --production 2>&1 | tail -3 && (ln -sf "$(npm root -g)/openclaw" node_modules/openclaw 2>/dev/null || ln -sf "$(dirname "$(which openclaw)")/../lib/node_modules/openclaw" node_modules/openclaw) && ls node_modules/openclaw/package.json >/dev/null 2>&1 && echo "READY" || echo "FAILED"
READY → 继续第 2 步The skill installs a plugin into the user's home directory (~/.openclaw/extensions/...), creating persistent state that survives the current session. Persistent installation is not inherently malicious, but in this context it modifies the agent runtime and leaves behind executable code and account material without emphasizing trust verification, rollback, or cleanup.
直接安装兼容的 legacy 版本,不需要做版本检查:
cd /tmp && npm pack @tencent-weixin/openclaw-weixin@legacy 2>&1 | tail -1 && rm -rf ~/.openclaw/extensions/openclaw-weixin && mkdir -p ~/.openclaw/extensions/openclaw-weixin && tar -xzf /tmp/tencent-weixin-openclaw-weixin-*.tgz -C ~/.openclaw/extensions/openclaw-weixin --strip-components=1 && cd ~/.openclaw/extensions/openclaw-weixin && npm install --production 2>&1 | tail -3 && (ln -sf "$(npm root -g)/openclaw" node_modules/openclaw 2>/dev/null || ln -sf "$(dirname "$(which openclaw)")/../lib/node_modules/openclaw" node_modules/openclaw) && ls node_modules/openclaw/package.json >/dev/null 2>&1 && echo "READY" || echo "FAILED"
READY → 继续第 2 步The skill instructs the agent to persist live authentication material (bot_token, baseurl, ilink_user_id) into local files under ~/.openclaw/... without any user consent prompt, retention guidance, or warning that long-lived credentials are being stored. Even though the file mode is set to 0600, this still creates a recoverable secret on disk that may be exposed through backup systems, later compromise of the host account, or other local tooling.
Detected: suspicious.destructive_delete_command