wechat-local-vault
Analyze Your Local WeChat Archive
WeChat Mac data is encrypted and difficult to search or export. This skill builds a local vault for authorized queries, exports, and summaries.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "wechat-local-vault" from https://skillstore.io/skills/mcncarl-wechat-local-vault.md and its manifest at https://skillstore.io/api/skills/mcncarl-wechat-local-vault/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "wechat-local-vault". Check the local vault status and show only operational details.
Expected outcome:
- Eight known databases are available, and two require updated keys.
- The latest successful refresh completed today.
- Plaintext data remains in the configured private vault.
Using "wechat-local-vault". Summarize the selected group between May 1 and May 7.
Expected outcome:
The digest covers 246 messages across four main topics. It lists two decisions, three open questions, and the most active contributors.
Using "wechat-local-vault". Find pending customer follow-ups from the last 30 days.
Expected outcome:
Three follow-ups remain open. Each item includes the conversation date, the stated commitment, current status, and a concise reply recommendation.
Security Audit
CriticalThe skill intentionally instruments WeChat, captures reusable cryptographic material, decrypts private databases, and exports plaintext conversation data. No application exfiltration was found, but unsafe temporary storage, plaintext keys, generated-source injection, and broad host modifications create serious local risk.
Confirmed security concerns (83)
Show all 83 confirmed findings
Capability review items (27)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Filesystem access (50)
๐ Env variables (19)
โ๏ธ External commands (50)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/mcncarl-wechat-local-vault/audits/3?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/mcncarl-wechat-local-vault?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/mcncarl-wechat-local-vault?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/mcncarl-wechat-local-vault/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/mcncarl-wechat-local-vault.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
mcncarl. (2026). wechat-local-vault security audit report (audit version 3) [Author version unspecified]. Skillstore. https://skillstore.io/skills/mcncarl-wechat-local-vault/audits/3BibTeX citation
@techreport{mcncarl-mcncarl-wechat-local-vault-2026,
author = {mcncarl},
title = {wechat-local-vault security audit report (audit version 3)},
institution = {Skillstore},
year = {2026},
number = {3},
url = {https://skillstore.io/skills/mcncarl-wechat-local-vault/audits/3},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "wechat-local-vault security audit report (audit version 3)"
version: "unspecified"
type: report
authors:
- name: "mcncarl"
date-released: "2026-07-11"
url: "https://skillstore.io/skills/mcncarl-wechat-local-vault/audits/3"
identifiers:
- type: other
value: "skillstore:mcncarl-wechat-local-vault:audit:3"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Review a Personal Conversation
Export one authorized conversation and analyze its timeline, tone, decisions, and follow-up items.
Prepare a Group Digest
Create a bounded source package and summarize topics, participation, decisions, and unresolved questions.
Track Customer Follow-Ups
Search authorized customer chats for commitments, unanswered questions, and recent activity within a defined period.
Try These Prompts
Check my authorized local WeChat vault status. Report available databases, missing keys, data freshness, and privacy-sensitive output locations.
Export my conversation with [contact or group] from [start date] to [end date]. Use the smallest necessary scope and save a readable report.
Build a digest source package for [group] covering [date range]. Summarize major topics, decisions, contributors, and unresolved items without exposing unnecessary messages.
Search authorized chats with [customer] for the last [period]. Identify commitments, unanswered questions, sentiment changes, and recommended follow-ups with supporting dates.
Best Practices
- Confirm ownership and authorization before accessing any WeChat account or conversation.
- Use narrow contacts and date ranges before full decryption or broad exports.
- Keep keys, plaintext databases, and reports in private local directories with restrictive permissions.
Avoid
- Do not inspect another person's account, device, or conversations without explicit authorization.
- Do not place plaintext databases or reusable keys in shared folders, repositories, or cloud storage.
- Do not request full archives when a bounded conversation or date range answers the question.
Frequently Asked Questions
Which WeChat versions are supported?
Does the skill send data over the network?
Where are decrypted databases stored?
Can it read image contents?
Is key extraction safe?
Can it update only recent data?
Developer Details
Author
mcncarlLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
c0271103e9d6ff62c5aa5b85e8fbc03aad6fc662
Maintenance freshness
7/18/2026
Usage
8 downloads ยท 1 views
File structure
๐ scripts/
๐ decrypt_all_dbs.py
๐ export_chat.py
๐ extract_keys.py
๐ list_contacts.py
๐ search_sns.py
๐ vault_cli.py
๐ wechat_digest.py
๐ README.md
๐ SKILL.md