post-to-wechat

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is largely aligned with its stated purpose: publishing to WeChat via official API or browser automation. Main risks come from public posting capability, local handling of raw API credentials, Bun install hygiene, and transitive trust in a separate markdown-to-html skill. No strong signs of malware or deceptive exfiltration are present, but the skill should be treated as medium-high risk because it can perform real-world publishing actions and store credentials locally.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 11:11 AM
Package URL
pkg:socket/skills-sh/GPTtang%2Fskill-atlas%2Fpost-to-wechat%2F@f26b67d22993d0d804b6b1576b5ec5471d4b2f9d3cc7f4f3b7b767342c302aa4
Security Audit — socket — post-to-wechat