add-wechat

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill mostly matches its stated purpose of adding a WeChat channel, and there is no clear credential exfiltration or proxying to a third-party endpoint. However, it pulls executable adapter code from an unpinned Git branch tied to whatever `origin` is configured, installs an external client library, and enables autonomous messaging through a personal WeChat account. This is a coherent but moderately risky integration rather than confirmed malware.

Confidence: 81%Severity: 59%
Audit Metadata
Analyzed At
Apr 26, 2026, 09:53 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fadd-wechat%2F@a966f64dbc238007891d3df61d33da783f66e029