tentacle-post2wechat

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core concern is not the WeChat publishing goal but the hidden intermediary: all content and the API key flow through api.tentacle.pro, which performs server-side credential mapping and token handling instead of using official WeChat APIs directly. The automatic invocation of another skill further widens trust. This is a coherent publisher workflow, but its data flow and credential model are overly centralized in a third-party gateway.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 13, 2026, 08:56 AM
Package URL
pkg:socket/skills-sh/tentacle-pro%2Fskills%2Ftentacle-post2wechat%2F@90efbaf747f76c1c02eaf02e023bcdbec0a5d4f2