Agent skill

WeChat Group Activity Stats

by punk2898 in punk2898/wechat-group-stats

Counts messages per member in a WeChat group on macOS, tags how active each person is, and shows the results in a web dashboard with a JSON API.

MITAuto-check: notesData & Analytics

Install WeChat Group Activity Stats

skills CLI
$ npx skills add punk2898/wechat-group-stats --skill wechat-group-stats -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install punk2898/wechat-group-stats wechat-group-stats --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wechat-group-stats
GitHub stars
121
Token cost
~2.8k tokens
SKILL.md length
1,139 words
Files
164
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Counts messages per member in a WeChat group on macOS, tags how active each person is, and shows the results in a web dashboard with a JSON API.

  • Works in 7 steps: Check Prerequisites → Re-sign WeChat (one-time) → Extract Keys → …
  • Finding out which members of a WeChat group are active
  • SKILL.md covers Overview, When to Use, Quick Start (for the Agent) and Database Schema Reference, plus 5 more sections
  • Runs Python, JavaScript and Shell scripts from its folder; calls python3, git and pip; reaches github.com

What it does

The skill guides you through a three-part pipeline: decrypt WeChat's local encrypted SQLite database on macOS, analyze group chat activity, and serve a dark-themed web dashboard. It reports per-member message counts for all time and for the last one, three and six months, assigns activity tags from very active down to inactive, and exposes a JSON API for automation. One use is spotting inactive members to remove.

Prerequisites are macOS, WeChat 4.x and an admin password. The project folder holds wechat-stats.py, dashboard.html and wechat-server.py, while the decryption engine, ylytdeng/wechat-decrypt, is installed separately. Setup checks that WeChat is present, re-signs the WeChat app once so its Hardened Runtime no longer blocks memory access, and runs a key-extraction step with sudo that writes all_keys.json. Both steps need admin rights, and re-signing removes a macOS protection from the WeChat app.

When your agent uses it

  • Finding out which members of a WeChat group are active
  • Listing inactive members before cleaning up a group
  • Setting up a recurring activity dashboard for a group
  • Setting up WeChat database decryption for analytics

Example prompts

  • “Analyze my WeChat group activity and show who has been silent for three months.”
  • “Check who is active in my group and launch the dashboard.”
  • “Help me set up the WeChat database decryption so I can run the group stats.”

Requirements

  • macOS with WeChat 4.x installed
  • Admin (sudo) access
  • The wechat-decrypt engine, installed separately
  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Check Prerequisites
  2. Re-sign WeChat (one-time)
  3. Extract Keys
  4. Decrypt Database
  5. Set Custom Group Name (one-time)
  6. Run Analysis
  7. Launch Dashboard

What it can do on your machine

Read from SKILL.md and the folder at commit 1987714. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python, JavaScript and Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • git
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

WeChat Group Activity Stats loads about 2.8k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 1,139 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:73
    sudo codesign --force --sign - /Applications/WeChat.app
  • NoteRuns commands with sudoSKILL.md:89
    sudo ./find_all_keys_macos
  • NoteRuns commands with sudoSKILL.md:173
    s "Full Disk Access" for Terminal.** If `sudo codesign` fails with `Operation not permitted / In subcomponent: ...WeChat
  • NoteRuns commands with sudoSKILL.md:175
    eChat.app ~/Desktop/WeChat_signed.app && sudo codesign --force --sign - ~/Desktop/WeChat_signed.app`, then run the signe
  • NoteRuns commands with sudoSKILL.md:201
    - [ ] `sudo ./find_all_keys_macos` produced `all_keys.json` (no `task_for_pid` error)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from punk2898/wechat-group-stats at commit 1987714, republished under its MIT licence (© punk2898). 1,139 words, ~2,781 tokens.

Download SKILL.mdSave it as .claude/skills/wechat-group-stats/SKILL.md (or your agent's skills folder). This skill also uses 163 other files; get the full folder from GitHub.
name
wechat-group-stats
description
Use when user wants to analyze WeChat group member activity — count messages per member, rank by recent activity, identify inactive members to remove, or build an activity dashboard. Covers full pipeline: decrypt local WeChat DB → extract group member stats → launch web dashboard.
version
1.0.0
author
punk2898
license
MIT

WeChat Group Activity Stats

Overview

Extracts group chat activity from WeChat's local encrypted SQLite database on macOS. Gives you: per-member message counts (total / 1mo / 3mo / 6mo), activity tags (🔥超活跃 → 💀死号), an interactive dark-themed web dashboard, and a JSON API for automation.

The full pipeline: decrypt → analyze → dashboard. Agent guides the user through each step, handling platform quirks and permissions.

Prerequisites: macOS, WeChat 4.x installed, admin password (sudo).

Tool directory: ~/wechat-group-stats/ (this project — contains wechat-stats.py, dashboard.html, wechat-server.py). The upstream decryption engine (ylytdeng/wechat-decrypt) should be installed separately at ~/wechat-decrypt/.

When to Use

  • User says: "analyze my WeChat group activity", "check who's active in my group", "WeChat group stats"
  • User wants to identify inactive members to remove
  • User wants a recurring activity dashboard
  • User asks about setting up WeChat DB decryption for analytics

Quick Start (for the Agent)

When the user asks to analyze a WeChat group, guide them through this sequence:

1. Check Prerequisites
bash
# Verify WeChat is installed
ls /Applications/WeChat.app

# Check if wechat-decrypt is already set up (external dependency)
ls ~/wechat-decrypt/find_all_keys_macos ~/wechat-decrypt/decrypt_db.py

# Check if this project is cloned
ls ~/wechat-group-stats/wechat-stats.py

If wechat-decrypt isn't set up, clone and install:

bash
git clone https://github.com/ylytdeng/wechat-decrypt.git ~/wechat-decrypt
cd ~/wechat-decrypt
python3 -m venv .venv && source .venv/bin/activate
pip install pycryptodome zstandard pilk tqdm
cc -O2 -o find_all_keys_macos find_all_keys_macos.c -framework Foundation

If wechat-group-stats isn't cloned:

bash
git clone <repo-url> ~/wechat-group-stats
2. Re-sign WeChat (one-time)

WeChat's Hardened Runtime prevents memory access. Re-signing removes it.

Ask the user to quit WeChat first, then run:

bash
killall WeChat
sudo codesign --force --sign - /Applications/WeChat.app

If codesign fails with "Operation not permitted":

  • Grant Terminal Full Disk Access in 系统设置 → 隐私与安全性 → 完全磁盘访问
  • Re-open Terminal and retry
  • Alternative: cp -R /Applications/WeChat.app ~/Desktop/ && sign the copy

Verify: codesign -dv /Applications/WeChat.app 2>&1 | grep flags should show flags=0x2(adhoc).

Then ask user to re-open WeChat and log in.

3. Extract Keys
bash
cd ~/wechat-decrypt
sudo ./find_all_keys_macos

Outputs all_keys.json. If it fails with task_for_pid: 5, the re-sign in step 2 didn't work — go back.

4. Decrypt Database

Auto-detects the db_storage path and creates config.json:

bash
cd ~/wechat-decrypt && source .venv/bin/activate
python3 decrypt_db.py

Decrypted DBs land in ~/wechat-decrypt/decrypted/.

5. Set Custom Group Name (one-time)
bash
python3 wechat-stats.py --set-name "群ID" "自定义群名"
# Example:
python3 wechat-stats.py --set-name "45379818937@chatroom" "链上前进四🚀"
6. Run Analysis
bash
python3 wechat-stats.py --group "链上前进四" --decrypted-dir ./decrypted

Outputs wechat-stats.json. If the group name isn't found, run without --group to list all groups, then pick the right one.

7. Launch Dashboard
bash
python3 wechat-server.py
# Opens at http://localhost:8080/dashboard.html

Dashboard features: member ranking, sortable columns, activity distribution bars, 🔄 one-click refresh button, search filter, tab to toggle active/inactive members.

Database Schema Reference

Full details in references/wechat-db-schema.md — includes the critical real_sender_id → wxid mapping chain discovered 2025-06-03, and why ext_buffer should NOT be used for group names.

Useful for custom queries beyond the built-in analysis:

TableLocationKey fields
Msg_<md5>message/message_0.dbreal_sender_id, create_time, source, message_content
SessionTablesession/session.dbusername (groups end with @chatroom), summary
chat_roomcontact/contact.dbusername, ext_buffer (protobuf: member list — NOT group name)
chatroom_membercontact/contact.dbroom_id, member_id → maps to contact.id
contactcontact/contact.dbid, username, nick_name, remark, alias

Mapping chain: Msg_<md5>.real_sender_id → extract wxid from message_content → contact.username → contact.nick_name/remark

Msg table hash: md5(group_username.encode()).hexdigest()

Data path (WeChat 4.x):

~/Library/Containers/com.tencent.xinWeChat/Data/Documents/
  xwechat_files/<wxid>/db_storage/{message,contact,session}/*.db

WeChat Encryption Parameters (4.x)

ParameterValue
SQLCipher version4
Page size4096
Reserve size80 (IV 16 + HMAC-SHA512 64)
KDF iterations256,000
KDF algorithmPBKDF2-HMAC-SHA512
HMACSHA-512 (64 bytes)

Common Pitfalls

  1. real_sender_id ≠ contact.id. The message table uses an internal sender ID space that does NOT match contact.id or chatroom_member.member_id. Must extract wxid from message_content (e.g. "wxid_xxx:\n内容") and match against contact.username. See references/wechat-db-schema.md for the full mapping chain and extraction code.

  2. Display name priority: remark(备注) > nick_name(昵称) > alias(别名) > username. Using alias > nick will show machine names like "XYiDao" instead of human names like "毅". For example: contact with alias="XYiDao", nick="毅" should display as "毅", not "XYiDao".

  3. WeChat wasn't quit before re-signing. Running binary/dylib files are locked — codesign fails. Always killall WeChat first. Common error: internal error in Code Signing subsystem / In subcomponent: ...libEGL.dylib.

  4. Re-signing needs "Full Disk Access" for Terminal. If sudo codesign fails with Operation not permitted / In subcomponent: ...WeChatAppEx.app, Terminal.app lacks FDA. Go to 系统设置 → 隐私与安全性 → 完全磁盘访问, add Terminal.app, then re-open Terminal and retry.

  5. --deep flag causes nested bundle failures. WeChat.app contains WeChatAppEx.app inside — --deep tries to recursively sign it and fails with Operation not permitted. Use codesign --force --sign - without --deep. Only the main bundle needs signing to unlock task_for_pid. If signing in /Applications still fails even with FDA (some macOS versions block writes there regardless), copy WeChat to Desktop first: cp -R /Applications/WeChat.app ~/Desktop/WeChat_signed.app && sudo codesign --force --sign - ~/Desktop/WeChat_signed.app, then run the signed copy.

  6. Key extraction needs WeChat running and ad-hoc signed. The C scanner (find_all_keys_macos) reads WeChat's process memory via mach_vm — this is blocked by Hardened Runtime (flags=0x10000). Error: task_for_pid failed: 5.

  7. WeChat updates will overwrite the ad-hoc signature. After a WeChat auto-update, you need to re-sign again and re-extract keys. The database encryption key may also change.

  8. Group names not stored locally in WeChat 4.x. The ext_buffer protobuf in chat_room contains member info but the group display name is fetched from the server and may not be in the local DB. Do NOT attempt to extract group names from ext_buffer — the protobuf's first Chinese string is typically a member's nickname (e.g. "秋刀鱼配柠檬"), not the group name. Use --set-name to assign custom names stored in group-names.json. Without a custom name, display as "群聊 (X人)" where X is the member count. The extract_group_name() function in wechat-stats.py is intentionally disabled and returns None.

  9. Analysis script reads already-decrypted DBs. After initial setup, daily refreshes only need step 6 (no sudo, no WeChat restart). Only re-run steps 3-4 if WeChat updated or you suspect key changes.

  10. Dashboard needs HTTP server. Opening dashboard.html directly from filesystem will fail to load wechat-stats.json due to CORS. Always use python3 wechat-server.py or python3 -m http.server 8080. The dedicated server also provides the /api/run endpoint for the one-click refresh button.

  11. WCDB compression in message_content. The WeChat message DB uses WCDB compression. About 30% of rows have WCDB_CT_message_content set to a non-zero value (typically 4), meaning message_content contains compressed binary — not readable text. When extracting wxid from message_content, always filter: AND (WCDB_CT_message_content IS NULL OR WCDB_CT_message_content = 0). Without this filter, LIMIT 1 has a ~30% chance of returning binary garbage, causing the wxid mapping to fail silently and the member's message count to stay at 0 (tagged as 💀死号). This can affect 60+ members in a large group. SQLite's LIKE operator triggers automatic decompression, so WHERE message_content LIKE '%wxid_%' would work too, but WCDB_CT_message_content = 0 is more explicit and avoids false matches.

Show full SKILL.md (151 more words)Show less

Publishing to GitHub (Privacy Sanitization)

If publishing a fork with these tools, ensure no private data leaks:

  • .gitignore must cover: wechat-stats.json (member names + stats), group-names.json (group ID mapping), all_keys.json (encryption keys), config.json (local paths), .venv/, decrypted/, wechat_files/.
  • Remove hardcoded group IDs: wechat-server.py uses WECHAT_GROUP_ID env var and --group= CLI arg. dashboard.html derives the group from loaded JSON data. No group IDs in committed source.
  • Provide example files: group-names.example.json with placeholder values like "YOUR_GROUP_ID@chatroom": "你的群名".
  • README use placeholders: Replace real group IDs with 你的群ID@chatroom in documentation examples.

Verification Checklist

  • codesign -dv /Applications/WeChat.app shows flags=0x2(adhoc)
  • sudo ./find_all_keys_macos produced all_keys.json (no task_for_pid error)
  • python3 decrypt_db.py succeeded: 17/17 or similar, no failures
  • python3 wechat-stats.py --group "group_keyword" produced valid JSON
  • http://localhost:8080/dashboard.html loads and shows member table
  • 🔄 refresh button works without errors

After Setup: Daily Use

Once everything is configured, the daily workflow is:

bash
cd ~/wechat-group-stats
python3 wechat-server.py
# → open http://localhost:8080/dashboard.html
# → click 🔄 刷新分析 anytime

No sudo, no WeChat restart, no key extraction — just one command + one click.

© punk2898, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 163 other files in the repository root of punk2898/wechat-group-stats.

  • SKILL.md
  • .gitignore
  • .push_state.json
  • README.md
  • _check.py
  • _post_score.py
  • _reset.py
  • dashboard.html
  • demo.png
  • docs/phase-1-plan.md
  • docs/schema.sql
  • ecosystem.config.cjs
  • group-names.example.json
  • last_sync.json
  • logs/error.log
  • logs/out.log
  • run_scoring.sh
  • score_messages.py
  • score_messages_v3.py
  • … and 145 more

Open the folder on GitHubat commit 1987714

Compare with similar skills

WeChat Group Activity Stats next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

WeChat Group Activity Stats compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
WeChat Group Activity Stats this skillpunk2898/wechat-group-stats121—~2.8kAutomated safety check: NotesMIT
Yichen Wecom Local Vaultmcncarl/yichen-skills4.4k—~1.3kAutomated safety check: PassCustom licence
Python Executorcortega26/chile-hub1132 repos~1.5kAutomated safety check: PassMIT
Environment SetupNorman-bury/research-writing-skill3.4k—~840Automated safety check: PassMIT
Raccoon DataanalysisSenseTime-Copilot/raccoon-dataanalysis-skill137—~1.9kAutomated safety check: PassNone
CSV Data Analysis5zjk5/prompt-engineering127—~2.6kAutomated safety check: PassNone

Similar skills

  • Yichen Wecom Local Vault

    mcncarl/yichen-skills

    Read, decrypt, query, search, and export local WeCom/企业微信 5.x desktop databases on macOS into a private read-only vault.

    4.4k GitHub stars~1.3k tokensUpdated 5 days ago
    Data & AnalyticsAuto-check passed
  • Python Executor

    cortega26/chile-hub

    Execute Python code in a safe sandboxed environment via [inference.sh](https://inference.sh).

    113 GitHub starsUsed in 2 repos~1.5k tokens
    Data & AnalyticsAuto-check passed
  • Environment Setup

    Norman-bury/research-writing-skill

    A skill your agent uses when Python environment setup is needed for data visualization or conda installation is required

    3.4k GitHub stars~840 tokensUpdated 4 mo ago
    Data & AnalyticsAuto-check passed
  • Raccoon Dataanalysis

    SenseTime-Copilot/raccoon-dataanalysis-skill

    Raccoon (小浣熊) Data Analysis - Remote code interpreter and data visualization service powered by SenseTime.

    137 GitHub stars~1.9k tokensUpdated 6 mo ago
    Data & AnalyticsAuto-check passed
  • CSV Data Analysis

    5zjk5/prompt-engineering

    This skill should be used when users need to analyze CSV or Excel files, understand data patterns, generate statistical summaries, or create data visualizations.

    127 GitHub stars~2.6k tokensUpdated 24 days ago
    Data & AnalyticsAuto-check passed
  • Convert a completed data-analysis conversation into evidence-backed, reproducible living research through the Krisk MCP server.

    117 GitHub stars~702 tokensUpdated 8 days ago
    Data & AnalyticsAuto-check passed

Questions about WeChat Group Activity Stats

What does WeChat Group Activity Stats do?

Counts messages per member in a WeChat group on macOS, tags how active each person is, and shows the results in a web dashboard with a JSON API. The skill guides you through a three-part pipeline: decrypt WeChat's local encrypted SQLite database on macOS, analyze group chat activity, and serve a dark-themed web dashboard. It reports per-member message counts for all time and for the last one, three and six months, assigns activity tags from very active down to inactive, and exposes a JSON API for automation.

When should I use WeChat Group Activity Stats?

WeChat Group Activity Stats fits situations like: finding out which members of a WeChat group are active; listing inactive members before cleaning up a group; setting up a recurring activity dashboard for a group; setting up WeChat database decryption for analytics.

How do I install WeChat Group Activity Stats in Claude Code?

Run `npx skills add punk2898/wechat-group-stats --skill wechat-group-stats -a claude-code`. Or copy the skill folder (the punk2898/wechat-group-stats repository) into .claude/skills/wechat-group-stats in your project. Claude Code loads it when a task matches its description.

How do I install WeChat Group Activity Stats in Codex?

Run `npx skills add punk2898/wechat-group-stats --skill wechat-group-stats -a codex`. Or copy the skill folder (the punk2898/wechat-group-stats repository) into .agents/skills/wechat-group-stats in your project. Codex loads it when a task matches its description.

Can I use WeChat Group Activity Stats in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add punk2898/wechat-group-stats --skill wechat-group-stats -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wechat-group-stats, .gemini/skills/wechat-group-stats, .github/skills/wechat-group-stats and .opencode/skills/wechat-group-stats in your project.

What does WeChat Group Activity Stats need to run?

Going by SKILL.md and its folder, WeChat Group Activity Stats needs Python, JavaScript and a shell for the scripts in its folder and the command-line tools its instructions call (python3, git and pip). Our summary lists: macOS with WeChat 4.x installed; Admin (sudo) access; The wechat-decrypt engine, installed separately; Python 3.

Does WeChat Group Activity Stats access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is WeChat Group Activity Stats safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does WeChat Group Activity Stats use?

WeChat Group Activity Stats is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does WeChat Group Activity Stats use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to WeChat Group Activity Stats?

Skills that share tags, products or a category with WeChat Group Activity Stats: Yichen Wecom Local Vault (mcncarl/yichen-skills, 4.4k stars), Python Executor (cortega26/chile-hub, 113 stars), Environment Setup (Norman-bury/research-writing-skill, 3.4k stars) and Raccoon Dataanalysis (SenseTime-Copilot/raccoon-dataanalysis-skill, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains WeChat Group Activity Stats?

punk2898 (a GitHub user) maintains it in punk2898/wechat-group-stats, which has 121 GitHub stars. The repository was last updated on June 9, 2026.

Source: punk2898/wechat-group-stats on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.