baoyu-post-to-wechat

Fail

Audited by Socket on Mar 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill is internally consistent with its stated WeChat publishing purpose: it reads expected config, uses official WeChat endpoints, and requests proportionate credentials. The main risks are autonomous public posting, transitive trust in a separate markdown skill, and official-but-still-risky Bun download/execute patterns. Overall this looks suspicious only in the sense of operational risk, not malicious intent or credential exfiltration.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Mar 25, 2026, 03:07 PM
Package URL
pkg:socket/skills-sh/zephyrwang6%2Fmyskill%2Fbaoyu-post-to-wechat%2F@504c48783157e7f74ad83d599692a8e0462140dd