Back to skill

Security audit

微信 PC 端自动控制

Security checks for vulnerabilities and agentic risk

Overview

The skill openly automates WeChat sending, but it can send messages and files through the user's account without recipient verification or confirmation.

Install only if you are comfortable letting an agent send WeChat messages, images, and local files from your logged-in account. Use it only with explicit recipient and content confirmation, avoid sensitive files, review batch manifests carefully, and prefer pinned dependencies in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/wechat_send.py:144
Finding

Unverified First Search Result Can Cause Messages or Files to Be Sent to the Wrong Recipient

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:55
Finding

Unpinned Third-Party Dependencies Are Installed Without Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README promotes automated sending of messages, images, files, and batch multi-group delivery, but does not prominently warn about misdelivery, privacy leakage, account misuse, or the risks of allowing other skills to call it as a push channel. In an agent ecosystem, this omission increases the chance that operators enable high-impact automation without understanding that one bad prompt, tool call, or contact match can broadcast sensitive data externally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented trigger phrases are broad natural-language patterns such as "微信发送 XXX" and "通过微信发给 XXX:内容", which can be matched accidentally in normal conversation or by other skills. Because this skill performs real outbound actions in a desktop messaging client, a false activation can send messages/files to unintended recipients and cause privacy or operational harm.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill exposes shell execution and file-reading capability through documented command-line invocation and access to local files, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, this can cause the host agent to grant broader-than-necessary capabilities implicitly, increasing the risk of unintended command execution, access to arbitrary local files, and abuse for exfiltration via WeChat automation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/wechat_send.py (reported line 82)May include surrounding context.

python
# 启动微信
    log("启动微信...")
    subprocess.Popen(WECHAT_PATH)
    time.sleep(6)

    # 等待微信窗口出现

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends text, images, and files directly to contacts once invoked, with no explicit user confirmation, dry-run preview, or recipient verification step before transmission. In an agent-automation setting this raises the risk of misdelivery, unauthorized outbound messaging, and accidental disclosure of sensitive files or content through prompt mistakes or malicious upstream tasking.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The screenshot feature captures the entire WeChat window, which may include unrelated conversations, contact lists, previews, and sensitive personal or business data beyond the intended message-send operation. Because the skill is designed for agent-driven automation, this creates a privacy and data-exfiltration risk if screenshots are stored, forwarded, or inspected by other components.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

README 明确写明窗口标题必须为中文“微信”而不是“WeChat”,这构成了对特定语言环境的硬性要求。文档没有提供用户可选择的语言/locale 方案,也没有将该限制表述为仅适用于特定中文安装环境的可选兼容条件。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.