wechat-cli-local-data
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s data-access behavior broadly matches its stated purpose, but it asks the agent/user to install and trust third-party code from publishers unrelated to ara.so, including a deprecated npm package and an unpinned personal GitHub repo. Given the tool extracts encryption keys from process memory and stores them locally, the weak install provenance is disproportionate to the sensitivity of the data it handles.
Confidence: 89%Severity: 78%
Audit Metadata