lov-wxmp-cracker
Fail
Audited by Snyk on Aug 24, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The package intentionally ships encrypted/opaque executable blobs and performs on-demand decryption (SKILL.md instructions + MANIFEST.enc.json listing), combined with a script named refresh_token.py — this deliberate concealment of runtime code prevents audit and is a strong sign the package could hide credential theft, data exfiltration, or backdoor/remote-exec behavior.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata