wechat-automation

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

No explicit malicious code patterns (obfuscation, hard-coded credentials, network exfiltration code, reverse shells) are present in the provided source. However, by design this agent exposes highly sensitive capabilities: reading private chat contents and injecting messages, and it funnels data to a generic stdout IPC channel without authentication or encryption. The module is therefore a high-risk component in a software supply chain if deployed in untrusted environments or paired with an untrusted orchestrator. Recommended actions before use: restrict run-time environment privileges, authenticate/authorize or encrypt the stdin/stdout IPC channel, sanitize/limit error outputs, add rate-limiting and command authorization for message-sending commands, and perform code review/audit of any orchestrator that consumes the agent's stdout.

Confidence: 75%Severity: 55%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:08 AM
Package URL
pkg:socket/skills-sh/cacr92%2Fwereply%2Fwechat-automation%2F@86d20c559d61c3306754249aa84f8c9c6d132976