weibo-webmcp

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's Weibo-reading/writing scope mostly matches its purpose and uses official Weibo domains, but it requires an unverifiable `uxc` CLI and enables autonomous public posting through an authenticated browser profile. The main concerns are install trust and real-world action capability rather than clear credential theft or confirmed malware.

Confidence: 80%Severity: 79%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:16 AM
Package URL
pkg:socket/skills-sh/holon-run%2Fwebmcp-bridge%2Fweibo-webmcp%2F@3308b31bf5b60f8a01d2c0824a9c184f354955c5