baoyu-wechat-summary

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for WeChat summarization, but it requires unsandboxed access to sensitive local chat stores and relies on a third-party CLI outside the publisher’s control. I found no explicit exfiltration, hidden behavior, or malicious pre-execution logic; the main risk is high-privilege access to private data plus supply-chain dependence on wx-cli.

Confidence: 88%Severity: 66%
Audit Metadata
Analyzed At
Jul 7, 2026, 02:27 PM
Package URL
pkg:socket/skills-sh/guanyang%2Fopen-agent-hub%2Fbaoyu-wechat-summary%2F@f1ebb796856553dd20845650d8047f4a5293583c6efa7d0bb568d4fe54d43e70
Security Audit — socket — baoyu-wechat-summary