wxauto-dev
Warn
Audited by Socket on Mar 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core WeChat automation purpose matches much of the skill, but its footprint is high-risk: it enables autonomous account actions and routes optional AI traffic and credentials through `api.dusapi.com`, a non-official intermediary for Claude-style models. This is not confirmed malware, but the third-party credential/data path and unattended social actions make the skill unsafe to trust by default.
Confidence: 84%Severity: 82%
Audit Metadata