wechat-minitest-ui

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a legitimate integration guide for running WeChat MiniTest automation, capturing screenshots, and performing UI image-diff checks. The instructions and capabilities align with the stated purpose. The primary security considerations are supply-chain and data-exfiltration risks inherent in executing local CLI commands and installing third-party test packages, and the expected flow of screenshots/reports to MiniTest cloud. There are no signs of obfuscated code, hidden exfiltration endpoints, credential-harvesting directives, or deceptive behavior. Recommended mitigations: run CLI commands and pip installs in a controlled environment, prefer pinned package versions when possible, review minium package contents before install, avoid uploading sensitive screenshots to cloud test if they contain secrets, and restrict agent autonomy so commands require explicit human approval.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 10:07 AM
Package URL
pkg:socket/skills-sh/wujun8%2Fagent-skills%2Fwechat-minitest-ui%2F@bdf816e21687556a091098af8f48e82a0a300865