wxwork-drive

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The business function is coherent, but the trust model is not: a minimally documented local wrapper reads raw enterprise credentials from `daemon.env` and sends them, plus file content, through a third-party relay outside the official WeChat Work API path. Because the core executable provenance is not documented or verifiable here, and it receives credentials, this skill carries high security risk even without proof of malicious intent.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Aug 1, 2026, 06:38 AM
Package URL
pkg:socket/skills-sh/teamwiseflow%2Fxiaobei%2Fwxwork-drive%2F@a6089181e8b787ce80439858e785cf2abae927ca350ca649f521207118fafab6
Security Audit — socket — wxwork-drive