wxauto-dev

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core WeChat automation purpose matches much of the skill, but its footprint is high-risk: it enables autonomous account actions and routes optional AI traffic and credentials through `api.dusapi.com`, a non-official intermediary for Claude-style models. This is not confirmed malware, but the third-party credential/data path and unattended social actions make the skill unsafe to trust by default.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Mar 22, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/cluic%2Fwxauto-skill%2Fwxauto-dev%2F@ed92ef46ced3d7a334387fa328d2a7f77cbc0434