What the reviewer found
A Feishu-to-WeChat-Official-Account sync skill: it stores the user's own WeChat AppID/AppSecret in ~/.claude/wechat-mp.json (chmod 600 to lock it down) and calls WeChat's official api.weixin.qq.com token endpoint, both the tool's stated purpose rather than remote code execution. The ifconfig.me call just looks up the machine's own IP for WeChat's required IP whitelist.
credential-access— reads credentialsnetwork— calls the vendor’s API
What was read
The file as it ships in CookiesHaha/ash-claude-skills:
plugins/ash-workflow/skills/lark-to-wechat-mp/SKILL.md
What the static scan said
The scan flagged 4things. The reviewer kept 0 and dismissed 4 as false.
PE2Asks for root — false positiveSC2Downloads and executes remote code — false positiveAS1Reads agent configuration directories — false positiveNETMakes network calls — false positive
How this review was made
Sonnet 5 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.