wechat-mp-writer
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core local article-rendering workflow is coherent with the stated purpose, but the skill materially expands into public posting and external-content ingestion through transitive skills and external script paths. No direct malicious behavior or credential theft is evident here, yet the delegated publish pipeline and skill-to-skill trust chain make it a medium-risk automation skill rather than benign documentation-only tooling.
Confidence: 80%Severity: 61%
Audit Metadata