lov-wxmp-cracker

Fail

Audited by Snyk on Aug 24, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The package intentionally ships encrypted/opaque executable blobs and performs on-demand decryption (SKILL.md instructions + MANIFEST.enc.json listing), combined with a script named refresh_token.py — this deliberate concealment of runtime code prevents audit and is a strong sign the package could hide credential theft, data exfiltration, or backdoor/remote-exec behavior.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 24, 2026, 12:57 AM
Issues
1
Security Audit — snyk — lov-wxmp-cracker