wxa-skills-generate
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
AnomalyAnomalyscripts/probe-lib.mjs
LOWAnomalyLOW
scripts/probe-lib.mjs
The code is a local WeChat mini-program API probing and automation utility. It does not show clear malware or supply-chain sabotage. Security concerns are primarily design-level: untrusted probe plans can execute arbitrary JavaScript through new Function, invoke arbitrary page methods and requests, and trigger destructive application actions if explicitly confirmed; captured traffic may contain credentials or personal data and is written to disk. Caller-controlled outputPath can write outside the project directory. Use only trusted plans, protect output files, and consider removing or isolating dynamic evaluate support.
Confidence: 97%Severity: 58%
Audit Metadata