lov-wdb-cli

Warn

Audited by Socket on Aug 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The claimed purpose matches WeChat data access, but the skill’s core behavior is hidden behind an encrypted, remotely decrypted package, so users cannot verify what will run before granting access to highly sensitive local chat data and keys. Official-looking distribution lowers pure malware certainty, but the combination of opaque runtime code, remote decryption, and sensitive local-data access makes this a high security-risk skill.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Aug 25, 2026, 02:24 AM
Package URL
pkg:socket/skills-sh/lovstudio%2Fskills%2Flov-wdb-cli%2F@c912ffcf6a46f1f79b1a430d3d0d0f6c54b4dfce23aac3999c1affacb96362b6
Security Audit — socket — lov-wdb-cli