weibo-webmcp
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's Weibo-reading/writing scope mostly matches its purpose and uses official Weibo domains, but it requires an unverifiable `uxc` CLI and enables autonomous public posting through an authenticated browser profile. The main concerns are install trust and real-world action capability rather than clear credential theft or confirmed malware.
Confidence: 80%Severity: 79%
Audit Metadata