baoyu-wechat-summary
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is purpose-aligned for WeChat summarization, but it requires unsandboxed access to sensitive local chat stores and relies on a third-party CLI outside the publisher’s control. I found no explicit exfiltration, hidden behavior, or malicious pre-execution logic; the main risk is high-privilege access to private data plus supply-chain dependence on wx-cli.
Confidence: 88%Severity: 66%
Audit Metadata