wechat-pipeline

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/VULNERABLE rather than confirmed malware. The overall purpose is coherent for WeChat article publishing, and the user-approval gates are a positive control. The main issue is disproportionate trust: an unverifiable md2wechat binary and transitive sub-skills receive WeChat credentials and publishing content, with hints of third-party service routing beyond official WeChat APIs. That combination makes the skill high security risk even though its stated workflow is plausible.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Jul 15, 2026, 07:53 AM
Package URL
pkg:socket/skills-sh/aaaaqwq%2Fclaude-code-skills%2Fwechat-pipeline%2F@be2ff1dc785a2aad32a643b34286baa72f03611c814c82081c6a562573c4379b
Security Audit — socket — wechat-pipeline