hermesclaw-wechat-multi-agent

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior mostly matches its stated purpose as a local WeChat token-sharing proxy, and runtime data flows appear aimed at official/local endpoints. However, the installation and trust model are high risk: a curl|bash installer from a personal GitHub repo, mutable branch execution, credential extraction from local account files, and modification of other tools’ configs/approval behavior make the footprint broader and less trustworthy than a typical routing helper.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fhermesclaw-wechat-multi-agent%2F@f8befa8654c761c8df7b99974f67f599a0161fb114312439b5804259e0a9211c
Security Audit — socket — hermesclaw-wechat-multi-agent