wxa-skills-generate

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/probe-lib.mjs

The code is a local WeChat mini-program API probing and automation utility. It does not show clear malware or supply-chain sabotage. Security concerns are primarily design-level: untrusted probe plans can execute arbitrary JavaScript through new Function, invoke arbitrary page methods and requests, and trigger destructive application actions if explicitly confirmed; captured traffic may contain credentials or personal data and is written to disk. Caller-controlled outputPath can write outside the project directory. Use only trusted plans, protect output files, and consider removing or isolating dynamic evaluate support.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 11, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/wechat-miniprogram%2Fai-mode-skills%2Fwxa-skills-generate%2F@8ff3a21acb118069f47435767ece5e4cb389ef9cc6df0c3377c2561854bbc82b
Security Audit — socket — wxa-skills-generate