weclaw-wechat-ai-bridge
Fail
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documentation promotes a 'One-line installer' command
curl -sSL https://raw.githubusercontent.com/fastclaw-ai/weclaw/main/install.sh | shwhich executes a script from an unverified remote source directly in the shell. - [EXTERNAL_DOWNLOADS]: The skill directs users to install unverified software including a Go package from
github.com/fastclaw-ai/weclawand a Docker image fromghcr.io/fastclaw-ai/weclaw. - [COMMAND_EXECUTION]: The skill facilitates system persistence by providing instructions to use
sudoto install service files in/etc/systemd/system/(Linux) or create aLaunchAgentin~/Library/LaunchAgents/(macOS). - [COMMAND_EXECUTION]: Configuration guidelines recommend using flags like
--dangerously-skip-permissionsand--skip-git-repo-checkfor integrated agents, which intentionally disables protective guardrails. - [DATA_EXFILTRATION]: The bridge manages files like
~/.weclaw/config.jsonand~/.weclaw/weclaw.logwhich store sensitive data including WeChat session tokens, conversation history, and API keys. - [COMMAND_EXECUTION]: The application dynamically spawns subprocesses based on user-defined binary paths in the configuration file, presenting a risk of unauthorized command execution.
- [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by bridging untrusted messages from WeChat to AI agents. 1. Ingestion points: WeChat messages via the weclaw bridge. 2. Boundary markers: Absent; message content is passed directly to agents. 3. Capability inventory: Subprocess execution of agent binaries and network requests. 4. Sanitization: Absent; the bridge only strips markdown for display purposes.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/fastclaw-ai/weclaw/main/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata