25smoking/Gwxapkg

一款基于GO实现的微信小程序 wxapkg解包工具,支持自动扫描、解密、反编译,小程序安全测试。

152Stars on the repository
9Mods indexed here, across every type
14d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

api-auth-analyzer

01

25smoking/Gwxapkg

Agent

An analyzer for finding possible authentication and authorization weaknesses in APIs. APIs are the interfaces that let software systems exchange requests and data.

not rated 152 +3 14d ago A 0 tokens original MIT

burp-correlator

02

25smoking/Gwxapkg

Agent

A tool for matching a raw Burp Suite HTTP request with the corresponding Gwxapkg source API, pseudocode, and call chain. Burp Suite is a web-security tool that records and edits HTTP requests.

not rated 152 +3 14d ago A 0 tokens original MIT

25smoking/Gwxapkg

Agent

A business-risk analyst that examines application workflows such as sign-in, verification codes, password resets, licence searches, orders, and payments.

not rated 152 +3 14d ago A 0 tokens original MIT

context-reader

04

25smoking/Gwxapkg

Agent

An agent that turns an unpacked Gwxapkg directory into a compact audit checklist. Gwxapkg is an unpacked WeChat Mini Program package, and the agent reviews its generated maps and reports.

not rated 152 +3 14d ago A 0 tokens original MIT

25smoking/Gwxapkg

Agent

An agent that checks whether a security evidence package covers the important parts of a codebase. It looks for missing files, APIs, endpoints, dynamic behavior, plugins, large archives, source maps, and unmatched requests.

not rated 152 +3 14d ago A 0 tokens original MIT

25smoking/Gwxapkg

Agent

An analysis agent for tracing encoding, encryption, signatures, device fingerprints, and fixed user-agent logic visible in front-end code. It distinguishes reversible encoding from encryption and signing, and records how fields flow through these operations.

not rated 152 +3 14d ago A 0 tokens original MIT

reporter

07

25smoking/Gwxapkg

Agent

An agent that turns analysis results into a Chinese security report and structured JSON. It records confirmed problems separately from risks that still need checking and links each finding to evidence such as file lines or packaged outputs.

not rated 152 +3 14d ago A 0 tokens original MIT

secret-triage

08

25smoking/Gwxapkg

Agent

An audit guide for reviewing suspected secrets in a JSON report, such as passwords, tokens, private-key fragments, phone numbers, and encoded text.

not rated 152 +3 14d ago A 0 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: