wechat-2d-render

Warn

Audited by Socket on Apr 27, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/render_wechat_2d.sh

No direct malware behaviors (credential theft/exfiltration/backdoor primitives) are evident in this bash wrapper itself. However, it is a high-sensitivity supply-chain execution harness: it clones or updates a remote repository from a default branch without pinning/signature/integrity verification, installs dependencies via pnpm (which can run lifecycle code), and executes repo-defined scripts (remotion:ensure-browser and remotion:render) with caller-provided props and output paths. If the remote repo or its dependencies are compromised, arbitrary code execution and unintended data/file/network actions are plausible.

Confidence: 66%Severity: 62%
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities are broadly aligned, but it instructs the agent to clone an unpinned third-party GitHub repo, install dependencies, and execute project scripts from the moving default branch. That is a real supply-chain risk, though there is no clear credential theft, covert behavior, or incompatible data exfiltration.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Apr 27, 2026, 04:00 AM
Package URL
pkg:socket/skills-sh/vibe-motion%2Fskills%2Fwechat-2d-render%2F@f0f1ac59741721ae8ec6d10201e6c1658bd2b2e0
Security Audit — socket — wechat-2d-render