T09 · Insecure Skill Coding Practices
- Location
scripts/wechat_send.py:144- Finding
Unverified First Search Result Can Cause Messages or Files to Be Sent to the Wrong Recipient
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill openly automates WeChat sending, but it can send messages and files through the user's account without recipient verification or confirmation.
Install only if you are comfortable letting an agent send WeChat messages, images, and local files from your logged-in account. Use it only with explicit recipient and content confirmation, avoid sensitive files, review batch manifests carefully, and prefer pinned dependencies in an isolated environment.
scripts/wechat_send.py:144Unverified First Search Result Can Cause Messages or Files to Be Sent to the Wrong Recipient
SKILL.md:55Unpinned Third-Party Dependencies Are Installed Without Integrity Verification
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The README promotes automated sending of messages, images, files, and batch multi-group delivery, but does not prominently warn about misdelivery, privacy leakage, account misuse, or the risks of allowing other skills to call it as a push channel. In an agent ecosystem, this omission increases the chance that operators enable high-impact automation without understanding that one bad prompt, tool call, or contact match can broadcast sensitive data externally.
The documented trigger phrases are broad natural-language patterns such as "微信发送 XXX" and "通过微信发给 XXX:内容", which can be matched accidentally in normal conversation or by other skills. Because this skill performs real outbound actions in a desktop messaging client, a false activation can send messages/files to unintended recipients and cause privacy or operational harm.
The skill exposes shell execution and file-reading capability through documented command-line invocation and access to local files, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, this can cause the host agent to grant broader-than-necessary capabilities implicitly, increasing the risk of unintended command execution, access to arbitrary local files, and abuse for exfiltration via WeChat automation.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# 启动微信
log("启动微信...")
subprocess.Popen(WECHAT_PATH)
time.sleep(6)
# 等待微信窗口出现
The script sends text, images, and files directly to contacts once invoked, with no explicit user confirmation, dry-run preview, or recipient verification step before transmission. In an agent-automation setting this raises the risk of misdelivery, unauthorized outbound messaging, and accidental disclosure of sensitive files or content through prompt mistakes or malicious upstream tasking.
The screenshot feature captures the entire WeChat window, which may include unrelated conversations, contact lists, previews, and sensitive personal or business data beyond the intended message-send operation. Because the skill is designed for agent-driven automation, this creates a privacy and data-exfiltration risk if screenshots are stored, forwarded, or inspected by other components.
README 明确写明窗口标题必须为中文“微信”而不是“WeChat”,这构成了对特定语言环境的硬性要求。文档没有提供用户可选择的语言/locale 方案,也没有将该限制表述为仅适用于特定中文安装环境的可选兼容条件。
No suspicious patterns detected.