跳到主要内容
知仓学习社ZHICANG

whatsapp

Send and receive WhatsApp messages via the unofficial linked-device client pywhats (pip install pywhats) — pair with QR, send text/images, group cha…

读凭据执行命令严重 0 · 高危 7sanjay3290/ai-skills

它会碰到什么

扫了多少5 个文本文件,50 KB
它会碰到什么读凭据执行命令
命中总数7 处
命中统计严重 0 · 高 7 · 中 0 · 低 0
逐条看命中(7 条严重或高危)
  • scripts/wa.py:43cred-envread
    stage = os.environ.get("_WA_BOOTSTRAP_STAGE", "0")
  • scripts/wa.py:44cred-envread
    home = pathlib.Path(os.environ.get("PYWHATS_HOME", pathlib.Path.home() / ".pywhats"))
  • scripts/wa.py:49cred-envread
    os.environ["_WA_BOOTSTRAP_STAGE"] = "1"
  • scripts/wa.py:59exec-spawn
    result = subprocess.run(["bash", bootstrap], stdout=subprocess.PIPE, text=True)
  • scripts/wa.py:64cred-envread
    os.environ["_WA_BOOTSTRAP_STAGE"] = "2"
  • scripts/wa.py:123cred-envread
    return pathlib.Path(os.environ.get("PYWHATS_HOME", pathlib.Path.home() / ".pywhats"))
  • scripts/wa.py:654cred-envread
    default=os.environ.get("PYWHATS_SESSION", "default"),

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

WhatsApp (pywhats)

Drive a WhatsApp account as a linked companion device (like WhatsApp Web)

from async Python via pywhats (pre-alpha,

text/image only). This is an unofficial multi-device client — not the

official WhatsApp Business / Cloud API.

CLI entrypoint: scripts/wa.py (auto-bootstraps a managed venv on first run).

Mental model

  • Pairing = one-time QR scan. wa.py pair shows an ASCII QR; scan it in

WhatsApp → Linked Devices. Credentials persist to

$PYWHATS_HOME/<session>.session (+ .signal.db).

  • Resuming = silent. Later commands reconnect with the same session — no QR.
  • JIDs address chats. Bare phone 1555000123415550001234@s.whatsapp.net;

groups use ...@g.us.

  • Events are how you receive. wa.py listen prints one JSON object per event.

⚠️ Never bare-await Client calls inside a handler

Event handlers run inline on the receive loop. Awaiting send_*,

mark_read, get_group_info, download_media, etc. inside a handler

deadlocks the connection. Always asyncio.create_task(...). The listen

subcommand already does this for --read.

Commands

scripts/wa.py pair                                          # one-time QR pair
scripts/wa.py send-text 15550001234 "hello"                 # 1:1 text
scripts/wa.py send-image 15550001234 photo.jpg --caption hi # 1:1 image
scripts/wa.py group-info 120363000000000000@g.us            # group metadata JSON
scripts/wa.py group-send 120363000000000000@g.us "hi all"   # group text
scripts/wa.py mark-read 15550001234 MSGID [--sender JID]    # blue ticks
scripts/wa.py presence available                            # global presence
scripts/wa.py typing 15550001234 composing [--media audio]  # typing indicator
scripts/wa.py listen --read --events message,receipt        # JSONL event stream
scripts/wa.py --session work send-text 15550001234 "hi"     # named session

| Command | Behavior |

|---------|----------|

| pair | Fresh link via ASCII QR; idempotent if already paired |

| send-text <to> <text> | Send 1:1 text; print message id |

| send-image <to> <path> [--caption C] | Send image (jpg/png/webp, ≤16MB); print id |

| group-info <gid> | Print group JSON (subject, owner, participants, …) |

| group-send <gid> <text> | Resolve members then send group text; print id |

| mark-read <chat> <ids...> | Blue-tick; --sender for groups |

| presence <available\|unavailable> | Global presence |

| typing <to> <composing\|paused> | Chat presence; optional --media audio |

| listen | Long-running JSON lines; --read, --events, --subscribe JID (required for presence events) |

Global: --session NAME (default default, or env PYWHATS_SESSION) —

goes before the subcommand: wa.py --session work pair.

Sessions / multi-account

$PYWHATS_HOME/                 # default: ~/.pywhats
  venv/                        # managed Python + pywhats
  default.session              # --session default
  default.session.signal.db
  work.session                 # --session work

Override home with PYWHATS_HOME. Unpaired / logged-out sessions print a clear

message to re-run wa.py --session <name> pair.

If pair reports the device was logged out right after scanning, that is

WhatsApp device-churn reaping, not a failure of the skill — the dead session is

deleted automatically; follow the recovery steps it prints (remove linked

devices, wait 15–20 min, pair once).

Full reference

[references/api.md](references/api.md) — every Client method, every event

payload, JID construction, and the download_media note.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 424
本站分层T2
该仓技能数24
原文件路径skills/whatsapp/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 24 个技能