wecom-automation

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior broadly matches its stated automation purpose, but it combines autonomous external actions, third-party token forwarding, and processing of untrusted inbound content with exec/write-capable tooling. This is not confirmed malware, yet it is a high-risk automation skill with significant trust and safety concerns.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:09 AM
Package URL
pkg:socket/skills-sh/aAAaqwq%2FAGI-Super-Team%2Fwecom-automation%2F@80ae6efc72a9ae1e556d3669091aac99b2c97f03