lovstudio-wxmp-cracker

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The claimed WeChat crawling purpose is plausible, but the skill’s real instructions are intentionally concealed behind a paid remote decryption step, it promotes transitive skill installation, and it relies on an unpinned GitHub-installed CLI that handles raw WeChat session credentials. This is not confirmed malware, but the hidden runtime-controlled behavior and credentialed external tooling make the skill high risk.

Confidence: 91%Severity: 88%
Audit Metadata
Analyzed At
Jul 29, 2026, 02:56 PM
Package URL
pkg:socket/skills-sh/lovstudio%2Fgeneral-skills%2Flovstudio-wxmp-cracker%2F@83d98eafdb4f983bce2413406c193887237f9f9a5c597fb8f8ad3535e5246563
Security Audit — socket — lovstudio-wxmp-cracker