skills/jackwener/wx-cli-again/wx-cli/Gen Agent Trust Hub

wx-cli

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PRIVILEGE_ESCALATION]: The core initialization and key retrieval processes (wx init and wx key extract) require execution with root or Administrator privileges. This level of access is used to scan the memory of other running processes (WeChat) to extract cryptographic keys from the heap.
  • [REMOTE_CODE_EXECUTION]: The project's documentation (README.md) suggests a high-risk installation method where a shell script is fetched from the project's GitHub repository and piped directly into the bash interpreter for execution.
  • [DYNAMIC_EXECUTION]: In the macOS implementation (src/scanner/macos.rs), the tool programmatically generates a Python script at runtime and executes it through the LLDB debugger to hook system-level cryptographic functions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted chat message data from the local WeChat database (ingestion point: src/daemon/query.rs). It lacks boundary markers or sanitization to separate message content from instructions, creating a surface where malicious content in a chat log could potentially influence the agent's behavior.
  • [EXTERNAL_DOWNLOADS]: The provided installation scripts (install.sh and install.ps1) fetch binary executables from GitHub Releases during the setup process.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/botiverse/wx-cli/main/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 03:07 PM
Security Audit — agent-trust-hub — wx-cli