hermesclaw-wechat-multi-agent
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s core behavior mostly matches its stated purpose as a local WeChat token-sharing proxy, and runtime data flows appear aimed at official/local endpoints. However, the installation and trust model are high risk: a curl|bash installer from a personal GitHub repo, mutable branch execution, credential extraction from local account files, and modification of other tools’ configs/approval behavior make the footprint broader and less trustworthy than a typical routing helper.
Confidence: 87%Severity: 78%
Audit Metadata