wechat-article-downloader

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core article-downloading behavior matches the stated purpose, but the skill expands into credential capture for bulk account access and routes some operations through a third-party MCP endpoint rather than official WeChat APIs. Provenance signals suggest the repo and domain are related, so this is not confirmed malware, but the combination of credential handling, opaque local tooling, and third-party remote processing makes the skill medium/high risk.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 18, 2026, 12:41 PM
Package URL
pkg:socket/skills-sh/qiye45%2FwechatDownload%2Fwechat-article-downloader%2F@fc1299b69fda2196cbed6dca8b7b3101fb11c91f
Security Audit — socket — wechat-article-downloader