wechat-cell-writer

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The article-writing and image workflow is broadly aligned with the stated purpose, but the trust boundary is too wide: WeChat credentials are prepared for use by a non-official posting skill, and execution relies on runtime package/browser downloads plus several companion skills. This looks more like a risky third-party automation stack than clear malware, with the main concern being credential forwarding and expanded supply-chain trust rather than overt exfiltration.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 16, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/xiaochuan886%2Fxiaochuan886-skills%2Fwechat-cell-writer%2F@374747e202ac0dc8381e67b2d74de1f6692e4906