wechat-styler

Warn

Audited by Socket on Jul 27, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the formatting/conversion features fit the stated purpose, but the skill expands into authenticated browser automation that can publish/save WeChat drafts using a third-party CLI and browser profile context. Install trust looks moderate rather than overtly malicious, and data flows target the official WeChat domain, but the automation and credential/session scope are broader and riskier than a pure Markdown-to-HTML styling skill.

Confidence: 85%Severity: 64%
AnomalyLOW
scripts/wechat-publish-core.mjs

No clear evidence of overt malware is present. However, the module includes a high-impact capability to inject arbitrary (decoded) HTML into a live rich-text editor via bodyEditor.innerHTML with no sanitization in this module. If upstream callers can be attacker-influenced, this creates a substantial DOM XSS/content-injection risk. Verification/probing functions primarily collect state and apply image-host allowlisting, which does not mitigate the injected-markup execution risk.

Confidence: 72%Severity: 61%
Audit Metadata
Analyzed At
Jul 27, 2026, 04:56 PM
Package URL
pkg:socket/skills-sh/zjp1997720%2Fzhijian-skills%2Fwechat-styler%2F@64723f38246efa3aafb9fd77bb1e7ee49a6949485d4a226aa0ec65ab6790016e
Security Audit — socket — wechat-styler