Wechat Search Weread
PassAudited by VirusTotal on May 16, 2026.
Findings (1)
The skill bundle automates WeChat article searching via WeChat Read using high-risk system and browser manipulation techniques. Most notably, 'references/wsl-cdp-browser.md' instructs the agent to modify Windows firewall and network settings using 'netsh' to expose the browser's Chrome DevTools Protocol (CDP) port to the network, which is a significant security risk. The 'SKILL.md' and 'references/extraction-pattern.md' files utilize extensive JavaScript injection ('eval') and direct CDP WebSocket communication to intercept 'window.open' calls and bypass UI limitations. Furthermore, the instructions are highly prescriptive, commanding the agent to skip standard verification steps (like snapshots) and follow specific execution patterns to ensure the automation succeeds, which effectively overrides default safety behaviors.
