wecom-doc-manager

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能的功能范围与“企业微信文档管理”基本一致,未见明显恶意取证或越权取密行为,因此不像恶意技能。但其核心依赖 `wecom_mcp` 和 `wecom-preflight` 都缺少可验证来源与发布链,且真实认证/网络数据流被黑盒工具隐藏,整体应判定为 SUSPICIOUS 而非 BENIGN。

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Mar 20, 2026, 11:41 AM
Package URL
pkg:socket/skills-sh/WecomTeam%2Fwecom-openclaw-plugin%2Fwecom-doc-manager%2F@4f7c8b70ca9aa6ac96737d3e241655cac045a0ea