wechat-watch
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches WeChat monitoring and Feishu push, but the skill expands trust to an unpinned external GitHub service and then uses it for login/session handling. Automatic Feishu delivery is also a high-risk autonomous action, though aligned with the feature set. Main issue is supply-chain and delegated trust, not confirmed malware.
Confidence: 84%Severity: 76%
Audit Metadata