wechat-mp

Fail

Audited by Snyk on Aug 13, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill includes an explicit CLI example that takes an appid and secret as command-line arguments and requires "init credentials" for draft pushes, which encourages embedding secret values verbatim in commands/outputs and thus creates exfiltration risk.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 13, 2026, 02:19 AM
Issues
1
Security Audit — snyk — wechat-mp