activity-push

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core workflow is coherent for activity extraction and WeCom pushing, and its WeCom endpoints match the stated purpose. The main risks are a user-configurable MP_API_HOST that can receive feed data and optional API keys, raw env-file secret handling, unverifiable local helper-script provenance, and autonomous outbound posting to internal groups. This looks more like a high-risk automation skill than confirmed malware.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:10 PM
Package URL
pkg:socket/skills-sh/zuoa%2Faj-skills%2Factivity-push%2F@a779e9409b5d7321451b192d625f8960583c3b38