wx-cli-wechat-local-data

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core capability—local WeChat data extraction via memory scanning—is broadly aligned with its stated purpose, but the overall footprint is high-risk. It combines privileged memory access, decrypted local caching, invasive macOS security changes, raw remote installers, and a transitive skill-install step. The biggest concern is install/execution trust: the skill is published by ara.so while directing users to install and trust code from jackwener via npm, GitHub raw scripts, and skill registry commands.

Confidence: 85%Severity: 76%
Audit Metadata
Analyzed At
May 16, 2026, 04:26 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdevtools-skills%2Fwx-cli-wechat-local-data%2F@51dda83f3b7bc85a82e6dbc9dba1ae7512ba01fb