Back to skill

Security audit

企业微信通知提醒

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims by sending WeCom webhook messages, but its documented setup can expose the webhook key and its shell JSON construction can let message content be malformed or manipulated.

Review this before installing if the webhook reaches an important group. Avoid putting a live webhook key directly in shell history or cron task text, rotate any key already exposed that way, and be cautious about forwarding untrusted content into the script because quotes or crafted values can alter or break the JSON payload.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
send_weixin.sh:11
Finding

Webhook Secret Exposed Through Process Arguments and Persistent Scheduled-Task Configuration

Content
View full analysis
[mentioned_list] [mentioned_mobile_list]" echo "示例: $0 'key' 'text' '消息内容' 'user1,user2' '13800001111,@all'" exit 1 fi # 定义变量 WEBHOOK_KEY="$1" MSGTYPE="$2" CONTENT="$3" MENTIONED_LIST="$4" MENTIONED_MOBILE_LIST="$5" ``` `SKILL.md:48-75` documents embedding the webhook key directly in persistent task messages: ```bash openclaw cron add \ --cron "0 14 * * *" \ --agent main \ --message "执行:~/.openclaw/workspace/skills/weixin-webhook/send_weixin.sh 'your_key' 'text' '【健康提醒】请做提肛运动!' 'liujie'" \ --name "daily_kegel" \ --description "每日提肛提醒" \ --no-deliver openclaw cron add \ --cron "0 9 * * *" \ --agent main \ --message "执行:~/.openclaw/workspace/skills/weixin-webhook/send_weixin.sh 'your_key' 'text' '晨会即将开始,请准时参加' '@all'" \ --name "morning_meeting" \ --description "晨会通知" \ --no-deliver openclaw cron add \ --cron "0 17 * * *" \ --agent main \ --message "执行:~/.openclaw/workspace/skills/weixin-webhook/send_weixin.sh 'your_key' 'markdown' '【日报提醒】请在18:00前提交日报。1. 今日完成2. 遇到问题3. 明日计划'" \ --name "daily_report" \ --description "日报提醒" \ --no-deliver ``` ### Technical Analysis The WeCom webhook key is a bearer credential: knowledge of the key is sufficient to submit messages to the associated group webhook. The script requires this credential as its first positional command-line argument. Command-line arguments can be exposed through process-inspection interfaces while the script and `curl` are running. Manual invocations can also remain in shell history. ...[truncated 1628 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
send_weixin.sh:18
Finding

Unescaped Input Allows JSON Payload Injection and Message Manipulation

Content
View full analysis
Remediation
View remediation
0))' ) JSON_DATA=$( jq -n \ --arg content "$CONTENT" \ --argjson mentioned "$MENTIONED_JSON" \ '{ msgtype: "text", text: { content: $content, mentioned_list: $mentioned } }' ) ``` 7. Apply the same serializer-based construction to Markdown and mobile-mention payloads. 8. Add tests covering quotes, backslashes, Unicode, multiline text, empty mention elements, commas, and attempted property injection. 9. Invoke `curl` with failure reporting, capture its exit status, and verify the WeCom response code so malformed or rejected messages cause a clear nonzero script exit. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · send_weixin.sh (reported line 50)May include surrounding context.

sh
# 发送请求
echo "发送的JSON数据:$JSON_DATA"
response=$(curl -s -X POST "https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=$WEBHOOK_KEY" \
  -H "Content-Type: application/json" \
  -d "$JSON_DATA")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This shell script performs an outbound HTTP POST and includes the webhook key directly in the request URL. Although it prints the JSON payload, there is no warning, prompt, or comment disclosing that a credential-like token will be sent to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-visible comments and command-line messages are written only in Chinese, including usage and error output. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.