add-wechat
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the overall purpose is coherent for a WeChat channel skill, and data flows appear to target Tencent endpoints, but the trust story is inconsistent. The skill markets the integration as official Tencent API support while installing a third-party reverse-engineered client and copying mutable branch content without pinning. Risk is elevated by supply-chain trust and local session-file handling, not by confirmed malware or overt exfiltration.
Confidence: 87%Severity: 66%
Audit Metadata