wechat-article-writer

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Anomaly
AnomalyLOW
wechat-full.js

No clear evidence of classic malware (e.g., backdoor, credential theft, or network exfiltration) is present in the shown code. However, the module embeds Markdown-derived fields into HTML output via direct string concatenation without escaping/sanitization. This creates a strong stored/preview XSS and HTML injection risk in the generated article.html/article-plain.html and potentially in the screenshot rendering context (where injected scripts could execute during Playwright rendering). Additionally, the script copies generated content to the system clipboard and opens a browser preview, increasing the operational impact of injected content.

Confidence: 65%Severity: 66%
Audit Metadata
Analyzed At
Aug 2, 2026, 01:45 AM
Package URL
pkg:socket/skills-sh/konglong87%2Fmethodology-skills%2Fwechat-article-writer%2F@9b010fc878e0801d00bad6884b97e9d177777b28340d8db6b506146719d7ae74
Security Audit — socket — wechat-article-writer