hermesclaw-wechat-multi-agent

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core behavior is mostly consistent with a WeChat multi-agent router, and data flows target the official iLink API, but the trust model is weak. It relies on an unpinned curl|bash installer from a personal repo, reads raw gateway credential files, patches third-party configs, and sets up persistent background services; these are proportionate enough to avoid a malware label, but they create meaningful security risk.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
May 17, 2026, 07:57 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fhermesclaw-wechat-multi-agent%2F@9fa2d78d6cd1c7cbead3f5eb56957c743e410a33
Security Audit — socket — hermesclaw-wechat-multi-agent