post-to-wechat

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly aligned with its stated WeChat publishing purpose, and the provided evidence suggests the app domain and GitHub repo are same-operator. However, it sends article content through a third-party rendering site and grants the agent browser-level control over a logged-in WeChat publishing session, enabling real-world posting actions. This is not confirmed malware, but it carries meaningful security and account-integrity risk due to intermediary data flow and autonomous backend automation.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 23, 2026, 07:02 AM
Package URL
pkg:socket/skills-sh/white0dew%2Fwechat-skill%2Fpost-to-wechat%2F@1e969599c8a1a2d27853644ec0421d3053d94831