wechat-safe-science-images

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it sources images from a whitelist, enforces licensing constraints, outputs auditable manifests and captions, and avoids content publication. There are no credential requirements or evident data exfiltration risks. The main area to monitor is the provenance and security of the commons_fetch.mjs script (its origin, integrity checks, and dependency handling). Overall, the risk is low to moderate (benign) with attention to supply-chain provenance of the CLI script.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 11:20 AM
Package URL
pkg:socket/skills-sh/xiaochuan886%2Fxiaochuan886-skills%2Fwechat-safe-science-images%2F@5c9a8b46cfc7db887d782977b5bc681460874e4e