baoyu-post-to-wechat

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill appears aligned with its stated purpose of posting to WeChat via API or browser automation, with support for article and image-text formats. While it employs necessary credential handling and automated browser interactions, the reliance on external runtimes (bun and Chrome) and broad environment access elevates the security risk. This is a non-malicious but moderately risky tool that should be used with explicit user consent, strict version pinning of runtimes, least-privilege credentials, secure logging, and ensured separation of credentials from public artifacts.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 04:21 PM
Package URL
pkg:socket/skills-sh/ideacco%2Fbaoyu-skills-openclaw%2Fbaoyu-post-to-wechat%2F@dae800f7e2489d2961200d882cf0a076c70d9fc0