wechat-pipeline
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/VULNERABLE rather than confirmed malware. The overall purpose is coherent for WeChat article publishing, and the user-approval gates are a positive control. The main issue is disproportionate trust: an unverifiable md2wechat binary and transitive sub-skills receive WeChat credentials and publishing content, with hints of third-party service routing beyond official WeChat APIs. That combination makes the skill high security risk even though its stated workflow is plausible.
Confidence: 84%Severity: 84%
Audit Metadata