wechat-article-maker

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/md/render.ts

No clear evidence of intentional malware (e.g., no explicit exfiltration, crypto-mining, reverse shells, or filesystem damage routines). However, the fragment has meaningful supply-chain and XSS-class security risks: it calls autoInstall() at runtime (implementation not shown), and it generates HTML by interpolating markdown-derived values into attributes/tags without consistent escaping or URL sanitization (notably in link/image rendering). If this HTML is served or opened in a browser, attacker-controlled markdown could result in script injection via unsafe href/src or raw HTML rendering depending on Marked configuration.

Confidence: 66%Severity: 72%
Audit Metadata
Analyzed At
May 1, 2026, 05:32 AM
Package URL
pkg:socket/skills-sh/alpha-hecoding%2Fawesome-skills%2Fwechat-article-maker%2F@916223c9a6788776c7ed7693d726a8b5459b1d2c