weclaw-wechat-ai-bridge

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core bridge behavior is consistent with the stated purpose, but the trust model is broad: a curl|sh installer from a different org than the skill publisher, forwarding of messages/tokens to external agent endpoints, unauthenticated API exposure when bound externally, and guidance to disable agent permission prompts. This looks more like a high-risk integration skill than confirmed malware.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Mar 23, 2026, 12:53 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fweclaw-wechat-ai-bridge%2F@3d776bbedc805004d65848906e4f6d6aada62a4e