Baoyu Wechat Summary

PassAudited by VirusTotal on May 14, 2026.

Findings (1)

This skill summarizes WeChat group chats by interfacing with the external 'wx-cli' tool. It explicitly instructs the agent to use 'dangerouslyDisableSandbox: true' to access sensitive local data, including WeChat's message database (~/Library/Containers/com.tencent.xinWeChat/) and configuration files (~//.wx-cli/). While the documentation in SKILL.md and the reference files (output-formats.md, profiles.md) includes detailed privacy guardrails and 'red lines' to prevent harmful content generation, the requirement to bypass sandbox protections to read private communications constitutes a high-risk capability. No evidence of intentional data exfiltration to external endpoints was found, but the broad access to personal data warrants a suspicious classification.