sqsl-style-cloner

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/clone_wechat_style.py

The fragment is a style-cloning and code-generation utility, not apparent malware. It performs user-requested URL/local-file reads and writes generated files. The main security issues are unsanitized style_name values used in filenames, which can enable path traversal during output generation, and unescaped display_name/article titles embedded in preview HTML, which can cause stored XSS when the preview is viewed. URL fetching can access any user-supplied HTTP(S) endpoint, but this is consistent with the stated purpose. Input validation, filename containment checks, and HTML escaping are recommended.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 20, 2026, 08:12 AM
Package URL
pkg:socket/skills-sh/sanqiushili%2Fsqsl-wechat-skill%2Fsqsl-style-cloner%2F@5ceaeb60b029a66ac1fdfcfcd449931d9b9dace3f2410b4e3953b4118f26dd09
Security Audit — socket — sqsl-style-cloner