add-wechat — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited add-wechat (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Adds WeChat support via iLink Bot API — the first-party Tencent API for personal WeChat bots (different from WeCom / Official Account).
Why this is different from wechaty/PadLocal:
NanoClaw doesn't ship channels in trunk. This skill copies the WeChat adapter in from the channels branch.
Skip to Credentials if all of these are already in place:
src/channels/wechat.ts existssrc/channels/wechat-registration.test.ts existssrc/channels/index.ts contains import './wechat.js';wechat-ilink-client is listed in package.json dependenciesOtherwise continue. Every step below is safe to re-run.
git fetch origin channelsgit show origin/channels:src/channels/wechat.ts > src/channels/wechat.ts
git show origin/channels:src/channels/wechat-registration.test.ts > src/channels/wechat-registration.test.tsAppend to src/channels/index.ts (skip if the line is already present):
import './wechat.js';pnpm install [email protected]pnpm run build
pnpm exec vitest run src/channels/wechat-registration.test.tsBoth must be clean before proceeding. wechat-registration.test.ts is the one integration test: it imports the real channel barrel and asserts the registry contains wechat. It goes red if the import './wechat.js'; line is deleted or drifts, if the barrel fails to evaluate (so the channel genuinely would not register), or if wechat-ilink-client isn't installed (the import throws) — so it also implicitly verifies the dependency from step 4. Importing is safe: the adapter opens its long-poll connection only in setup() (at host startup), never at import.
End-to-end message delivery against a real WeChat account is verified manually once the service is running — see Credentials and Wire your first DM above.
Unlike most channels, WeChat requires no pre-configured API keys. Auth happens via QR code scan from your phone.
Add to .env:
WECHAT_ENABLED=trueSync to container: mkdir -p data/env && cp .env data/env/env
Restart NanoClaw.
Run from your NanoClaw project root:
source setup/lib/install-slug.sh
systemctl --user restart $(systemd_unit) # Linux
# or
launchctl kickstart -k gui/$(id -u)/$(launchd_label) # macOSThe adapter will print a QR URL to the logs and save it to data/wechat/qr.txt:
tail -f logs/nanoclaw.log | grep WeChat
# or
cat data/wechat/qr.txtOpen the URL in a browser (it renders a QR code), then:
data/wechat/auth.json — do not commit this fileThe bot is now connected as your WeChat account.
A successful QR login alone isn't enough — the adapter still needs to be wired to an agent group before it can respond.
Have a different WeChat account send a message to the bot account. This auto-creates a messaging_groups row with the sender's platform_id.
pnpm exec tsx .claude/skills/add-wechat/scripts/wire-dm.tsInteractive flow: the script lists all unwired WeChat messaging groups, asks which agent group to wire it to, and creates the messaging_group_agents row with sensible defaults (sender policy request_approval, session mode shared).
With request_approval, the next DM from the stranger fires an approval card to the admin — admin taps Approve/Deny, approved users are added as members and their queued message replays through the agent.
Non-interactive:
pnpm exec tsx .claude/skills/add-wechat/scripts/wire-dm.ts \
--platform-id wechat:wxid_xxxxx \
--agent-group ag-xxxxx \
--non-interactiveFlags:
--platform-id <id> — wire a specific messaging group (default: most recent unwired)--agent-group <id> — target agent group (default: prompt; or solo admin group in non-interactive)--sender-policy public|strict|request_approval — default request_approval (fires an admin approval card on unknown-sender DMs)--session-mode shared|per-thread — default sharedHave the sender message the bot again — the agent should respond.
data/wechat/auth.json.WeChat: session expired in logs, delete data/wechat/auth.json and restart — you'll be asked to re-scan.data/wechat/sync-buf.txt holds the long-poll cursor. Deleting it replays recent history on next start; don't delete it in normal operation.If you're in the middle of /setup, return to the setup flow now.
Otherwise, restart the service to pick up the new channel and wiring.
wechatWeChat inbound platformId=wechat:<id>. Use wechat:<user_id> for DMs, wechat:<group_id> for rooms.init-first-agent.ts --admin-user-id) is saved to data/wechat/auth.json as operatorUserId after the QR scan. Read it with cat data/wechat/auth.json | jq -r .operatorUserId and prefix with wechat: (i.e. wechat:<operatorUserId>).shared session mode per messaging group (DM or room). Use strict sender policy if you want only specific users to reach the agent; public opens it to anyone who messages the bot.wire-dm.ts helper (see the "Wire your first DM" section above) if running this skill standalone. If running as part of bash nanoclaw.sh, init-first-agent.ts handles wiring — just pass the platform-id and admin-user-id captured above.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.