ai-model-wechat
Fail
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill’s footprint is coherent with its stated purpose: it provides a WeChat Mini Program specific integration to call AI models via the official cloud extension, with non-streaming and streaming modes and appropriate event callbacks. There are no evident credential handling, unverifiable binaries, or external data sinks beyond the Cloud AI provider. Risks are primarily tied to data privacy and the reliance on WeChat Cloud AI’s security posture, not to credential exposure or supply-chain issues. Overall risk is low to moderate, consistent with a purpose-built integration in a controlled platform.
Confidence: 98%
Audit Metadata