wechat-automation

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s monitoring and UI-control behavior largely matches its stated WeChat automation purpose, and data is described as flowing to a local orchestrator rather than an attacker-controlled endpoint. The main security concern is install-trust inconsistency around wxauto v4 packaging, plus the inherently sensitive nature of granting an AI-guided agent access to private chats and UI automation capable of messaging actions.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/cacr92%2Fwereply%2Fwechat-automation%2F@86d20c559d61c3306754249aa84f8c9c6d132976