企业微信通知提醒

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Enterprise WeChat webhook notifier with expected outbound messaging and optional scheduled reminders.

Install only if you intend to send Enterprise WeChat group notifications. Treat the webhook key like a password, avoid secrets or sensitive personal data in scheduled messages, test with harmless content first, and remove cron jobs you no longer need.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The scheduled-task examples instruct users to place message bodies, recipient identifiers, and the webhook key directly into cron/job definitions without warning that those values will be transmitted to the external WeCom webhook endpoint. In practice, this can cause unintended disclosure of sensitive operational content and contact identifiers, especially because scheduled jobs are often reused, logged, or inspected by other operators.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal