wechat-original-hot

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/generate_hot_html.py

No clear evidence of intentional malware (e.g., backdoor, exfiltration, cryptomining, reverse shell) in the provided Python fragment. However, the code constructs and persists an HTML file by directly embedding untrusted JSON/CLI-derived strings into HTML/attributes without escaping or input validation, creating a significant stored/reflective XSS risk when the generated HTML is opened. Additionally, the output page loads and executes a third-party PDF/export JavaScript library from a public CDN without integrity protection, increasing runtime supply-chain trust exposure. Fragment truncation/missing function definitions reduce certainty about exact reachability of all injection points, but the unsafe templating pattern is clearly present.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Sep 2, 2026, 12:31 PM
Package URL
pkg:socket/skills-sh/redfox-data%2Fredfox-community%2Fwechat-original-hot%2F@8f749513dbf9696e110a11ca315559fa463fde5a6012bed0322782a8f1f29aa9
Security Audit — socket — wechat-original-hot