Back to skill

Security audit

Huo15 Openclaw Wechat Service

Security checks for vulnerabilities and agentic risk

Overview

This is a real WeChat channel plugin, but its default settings can expose powerful account-management tools to public follower agents unless the operator tightens permissions.

Review before installing on any production official account. Set dynamicAgents.permissionMode to admin-only or role-based, configure adminUsers or roles, avoid the open default, review or disable defaultInstructionsPreset if you do not want Huo15-branded or lead-capture behavior, and enable knowledgeSync/Odoo only if conversation retention and access controls are acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/shared/authorization.ts:196
Finding

Default-Open Authorization Exposes Administrative WeChat Tools to Public User Agents

Content
View full analysis
| undefined; const section = (channels?.[CONFIG_SECTION_KEY] as { dynamicAgents?: { permissionMode?: string } } | undefined) ?? (channels?.[LEGACY_CONFIG_SECTION_KEY] as | { dynamicAgents?: { permissionMode?: string } } | undefined); const mode = section?.dynamicAgents?.permissionMode; if (mode === "admin-only") return "admin-only"; if (mode === "role-based") return "role-based"; return "open"; } ``` `src/shared/authorization.ts:254-257`: ```ts export function checkAuthorization(ctx: AuthorizationContext): AuthorizationDecision { const mode = getPermissionMode(ctx.cfg); if (mode === "open") { return { allowed: true }; } ``` `src/tools/shared.ts:123-148`: ```ts export function assertAuthorized(params: { ctx: ToolContext; apiConfig?: OpenClawConfig; toolName: string; action: string; accountId: string; }): ToolResult | null { const cfg = params.ctx.runtimeConfig ?? params.ctx.config ?? params.apiConfig; if (!cfg) return null; // Missing configuration is allowed rather than denied const decision = checkAuthorization({ cfg, toolContext: { agentId: params.ctx.agentId, requesterSenderId: params.ctx.requesterSenderId, senderIsOwner: params.ctx.senderIsOwner, }, accountId: params.accountId, toolName: params.toolName, action: params.action, }); if (decision.allowed) return null; return buildErrorResult({ action: params.action, error: decision.reason, permissionMode: "adm ...[truncated 4252 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
src/shared/personas/it-support.ts:103
Finding

Bundled Promotional Persona Is Persisted as Agent Instructions and Steers Future Sessions

Content
View full analysis
, agentId: string, instructions?: string, ): boolean { if (!cfg.agents || typeof cfg.agents !== "object") { cfg.agents = {}; } const agentsObj = cfg.agents as Record ...[truncated 5711 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (193)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 236)May include surrounding context.

md
#### 3) .gitignore / .npmignore 重组

- `.gitignore`:补齐凭据 / pem / bak / tgz / .npm / vitest cache / IDE swp 等漏项,结构化分组(依赖/构建/测试/打包/日志/IDE/系统/凭据/备份/本地)
- `.npmignore`:明确"package.json.files 是白名单优先级最高"的注释,补 .git/ / .cnb.cool/ / *.pem / credentials.json 等防误打包

验证:`npm pack --dry-run` → 303 KB / 317 文件,无 .test.ts / .env / coverage / .github 等垃圾。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 238)May include surrounding context.

md
- `.gitignore`:补齐凭据 / pem / bak / tgz / .npm / vitest cache / IDE swp 等漏项,结构化分组(依赖/构建/测试/打包/日志/IDE/系统/凭据/备份/本地)
- `.npmignore`:明确"package.json.files 是白名单优先级最高"的注释,补 .git/ / .cnb.cool/ / *.pem / credentials.json 等防误打包

验证:`npm pack --dry-run` → 303 KB / 317 文件,无 .test.ts / .env / coverage / .github 等垃圾。

### 兼容性

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CLAUDE.md (reported line 16)May include surrounding context.

md
├── monitor.ts               # 公共入口 re-export
├── dynamic-agent.ts         # 动态 Agent 派生(一粉一会话)
├── outbound.ts              # 主动消息下发
├── access-token.ts          # Access Token 管理与自动刷新
├── http-client.ts           # HTTP 客户端(含重试/代理)
├── crypto.ts                # 微信加解密(SHA1/AES)
├── auto-reply.ts            # 自动回复:关键词匹配 / 业务时间 / 欢迎语模板

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The overall pattern across the supplied findings is that the package is presented as a small truncation hotfix while exposing many operational WeChat tools, external integrations, storage, and policy behaviors. That mismatch is the core security issue: it undermines informed consent, least privilege, and change-control, making the skill more dangerous than the narrow release note suggests.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/access-token.ts:51

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/api/oauth.ts:123

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/tools/oauth-tool.ts:132