aws-wechat-article-publish

Warn

Audited by Socket on Apr 26, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/usage.md

The described workflow enables automated publication to WeChat using credentials stored in the repo. While not showing malicious code, the design introduces substantial supply-chain and operational risks due to hard-coded credentials in aws.env, configurable endpoints, and CLI-based publishing without explicit access controls or rotation. Mitigation should prioritize secret management, least-privilege per slot, strict access controls for publish actions, secure logging practices, and credential rotation/audit processes.

Confidence: 68%Severity: 62%
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability matches the stated purpose of publishing WeChat articles, and the required credentials/files are mostly proportionate. The main concerns are (1) optional routing through a custom API base that could intercept APPID/APPSECRET and article content, (2) encouragement to install a broader multi-skill suite, and (3) autonomous public publishing capability with real-world consequences. If constrained to official api.weixin.qq.com and used with explicit user approval, the skill appears coherent rather than malicious.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 26, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/aiworkskills%2Fwechat-article-skills%2Faws-wechat-article-publish%2F@285177d039b3fe0a6d72dfd097e2b0b4687c19ee