wechat-writing

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core writing/publishing workflow is coherent, and the WeChat draft flow appears intended for official APIs, but the skill is not self-contained: it delegates execution and credentials to multiple unpinned companion skills, processes untrusted web content, allows arbitrary illustration proxy endpoints, and performs account actions by default. This is better classified as a high-risk vulnerable skill than confirmed malware.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Apr 8, 2026, 01:44 AM
Package URL
pkg:socket/skills-sh/ZhanlinCui%2FSuper-Article%2Fwechat-writing%2F@1c828d22ade4f9ae6fc14fdf9187364c56b7d271