baoyu-wechat-summary

Warn

Audited by Socket on May 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches the capabilities, but the skill relies on a third-party wx-cli binary with full access to local WeChat data and requires sandbox disabling from the outset. There is no clear malicious or exfiltration behavior in the skill text itself, yet the privacy and execution-trust footprint is substantial and should be treated as medium risk.

Confidence: 87%Severity: 63%
Audit Metadata
Analyzed At
May 21, 2026, 07:46 AM
Package URL
pkg:socket/skills-sh/yelban%2Fbaoyu-skills.TW%2Fbaoyu-wechat-summary%2F@94ff103fb021bcb07d2363a21bcf7e81a4e89c48
Security Audit — socket — baoyu-wechat-summary