wechat-mp-smart-publish
Pass
Audited by Gen Agent Trust Hub on May 3, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The file browser-session.md contains a specific WeChat user identifier (wxuin=73757210043448) and details regarding Knowledge Planet (zsxq.com) session cookies. Storing specific account identifiers in shared project documentation represents a data exposure risk.
- [COMMAND_EXECUTION]: The scripts scripts/publish.py and scripts/api_publish.py perform automated browser interactions and API requests to manage content. These scripts process and store session cookies and authentication tokens in a local configuration directory (~/.openclaw/), which is an expected but sensitive operation requiring appropriate file system permissions.
- [EXTERNAL_DOWNLOADS]: The skill documentation and scripts specify dependencies on external tools and packages, including Playwright and its browser binaries. These downloads originate from well-known and trusted official registries and repositories.
Audit Metadata