wechat-auto-reply

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is an automation utility for WeChat on macOS that uses local OCR and UI automation to suggest and send replies. It does not show network exfiltration, obfuscated payloads, or explicit credential harvesting in the provided content. Primary risks are operational and privacy-related: the need for Screen Recording and Accessibility permissions (which allow reading all on-screen content and controlling input), automatic sending of messages when confidence ≥ 85% (possible unintended outbound messages), clipboard clobbering, and reliance on a third-party Homebrew tap for installation. These factors make the package a moderate security risk if granted permissions and run without care; it should not be installed or run on machines with sensitive information without evaluating trust in the tap/author and limiting permissions. Recommended mitigations: review/install from trusted sources only, require explicit per-message confirmation (disable automatic send), avoid running on accounts with sensitive open windows, and inspect installed binaries from the Homebrew tap before granting privileges.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 06:52 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fwechat-auto-reply%2F@31efeaf21b1f5cfa777e5f1383f541f6d216ba6a