wx-cli-wechat-local-data
Warn
Audited by Socket on May 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core capability—local WeChat data extraction via memory scanning—is broadly aligned with its stated purpose, but the overall footprint is high-risk. It combines privileged memory access, decrypted local caching, invasive macOS security changes, raw remote installers, and a transitive skill-install step. The biggest concern is install/execution trust: the skill is published by ara.so while directing users to install and trust code from jackwener via npm, GitHub raw scripts, and skill registry commands.
Confidence: 85%Severity: 76%
Audit Metadata