soia-pkm-clip-wechat-account
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts (fetch_api.py, fetch_cookie.py, fetch_mp.py) as its primary mechanism for retrieving and processing article data.\n- [EXTERNAL_DOWNLOADS]: The documentation references an installation command that fetches the skill package via npx from the author's public repository (soia-team/soia-open-skills).\n- [SAFE]: The skill demonstrates high security standards by requiring sensitive session data (cookies and tokens) to be stored in a private configuration file outside the vault and the skill's own repository.\n- [SAFE]: The skill includes explicit disclosures and requires user consent before using non-official WeChat backend interfaces, ensuring users are aware of potential platform service term implications.
Audit Metadata