lovstudio-wxmp-cracker
Warn
Audited by Socket on Jul 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The claimed WeChat crawling purpose is plausible, but the skill’s real instructions are intentionally concealed behind a paid remote decryption step, it promotes transitive skill installation, and it relies on an unpinned GitHub-installed CLI that handles raw WeChat session credentials. This is not confirmed malware, but the hidden runtime-controlled behavior and credentialed external tooling make the skill high risk.
Confidence: 91%Severity: 88%
Audit Metadata