baoyu-post-to-wechat

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/wechat-api.ts

This module appears to be a legitimate WeChat publishing CLI, but it has meaningful security risk. The primary concern is the ability to fetch arbitrary http(s) URLs provided in untrusted HTML (and via --cover/frontmatter) and then upload the fetched bytes to WeChat, enabling SSRF-like abuse and unintended data exfiltration if an attacker can influence the input HTML/cover URL. A secondary concern is the runtime execution of a renderer through 'npx -y bun', which increases supply-chain/toolchain exposure at execution time. No direct, clear malware/backdoor behavior is evident from the provided code alone.

Confidence: 72%Severity: 67%
Audit Metadata
Analyzed At
Jun 23, 2026, 01:51 AM
Package URL
pkg:socket/skills-sh/tangchunwu%2Fskill-hub%2Fbaoyu-post-to-wechat%2F@31760d49c7ede7ebed8751bcbf9ac78a574b4bc50bb0bdbead233a9e5a8c9de1
Security Audit — socket — baoyu-post-to-wechat