soia-pkm-clip-wechat-account

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (fetch_api.py, fetch_cookie.py, fetch_mp.py) as its primary mechanism for retrieving and processing article data.\n- [EXTERNAL_DOWNLOADS]: The documentation references an installation command that fetches the skill package via npx from the author's public repository (soia-team/soia-open-skills).\n- [SAFE]: The skill demonstrates high security standards by requiring sensitive session data (cookies and tokens) to be stored in a private configuration file outside the vault and the skill's own repository.\n- [SAFE]: The skill includes explicit disclosures and requires user consent before using non-official WeChat backend interfaces, ensuring users are aware of potential platform service term implications.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 08:21 AM
Security Audit — agent-trust-hub — soia-pkm-clip-wechat-account