wechat-watch

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches WeChat monitoring and Feishu push, but the skill expands trust to an unpinned external GitHub service and then uses it for login/session handling. Automatic Feishu delivery is also a high-risk autonomous action, though aligned with the feature set. Main issue is supply-chain and delegated trust, not confirmed malware.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Apr 2, 2026, 04:18 PM
Package URL
pkg:socket/skills-sh/maolai7%2Fagent-skills%2Fwechat-watch%2F@4841142295fc20ce6aab3fa5b2a8a3750ea2b915