add-wechat

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the overall purpose is coherent for a WeChat channel skill, and data flows appear to target Tencent endpoints, but the trust story is inconsistent. The skill markets the integration as official Tencent API support while installing a third-party reverse-engineered client and copying mutable branch content without pinning. Risk is elevated by supply-chain trust and local session-file handling, not by confirmed malware or overt exfiltration.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Aug 19, 2026, 07:38 AM
Package URL
pkg:socket/skills-sh/nanocoai%2Fnanoclaw%2Fadd-wechat%2F@e491bf4acfa7833ce2b1378a048fb67f35e0174c397818e3076ed011d617dedd
Security Audit — socket — add-wechat