wecomcli-edit-todo

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s purpose and command set are coherent for editing WeCom todos, and there is no direct evidence of credential theft or deceptive exfiltration in the text. However, the entire skill depends on an unverifiable external CLI whose publisher, install path, credential handling, and network endpoints could not be confirmed from official sources, so the skill is best classified as SUSPICIOUS with high supply-chain risk rather than confirmed malware.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/WeComTeam%2Fwecom-cli%2Fwecomcli-edit-todo%2F@5d9fbdd145c9366e3c59c580f27adff1ccd32de5