She Love Me
863401402/she-love-me
Acquire, import, and analyze WeChat or QQ chat histories, including installing supported exporters, guiding required login or contact selection, converting exports, assessing relationship dynamics…
A skill your agent uses when auditing a Gwxapkg unpacked WeChat Mini Program directory with LLM assistance; consumes .gwxapkg semantic artifacts, route maps, sensitivereport.json, and optional Burp…
$ npx skills add 25smoking/Gwxapkg --skill gwxapkg-ai-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install 25smoking/Gwxapkg gwxapkg-ai-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/25smoking/Gwxapkg.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gwxapkg-ai-audit .claude/skills/gwxapkg-ai-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gwxapkg-ai-audit" agent skill from https://github.com/25smoking/Gwxapkg/tree/main/skills/gwxapkg-ai-audit into .claude/skills/gwxapkg-ai-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gwxapkg-ai-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/25smoking/Gwxapkg/tree/main/skills/gwxapkg-ai-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add 25smoking/Gwxapkg --skill gwxapkg-ai-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install 25smoking/Gwxapkg gwxapkg-ai-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/25smoking/Gwxapkg.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/gwxapkg-ai-audit .agents/skills/gwxapkg-ai-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gwxapkg-ai-audit" agent skill from https://github.com/25smoking/Gwxapkg/tree/main/skills/gwxapkg-ai-audit into .agents/skills/gwxapkg-ai-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gwxapkg-ai-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 25smoking/Gwxapkg --skill gwxapkg-ai-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install 25smoking/Gwxapkg gwxapkg-ai-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/25smoking/Gwxapkg.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/gwxapkg-ai-audit .cursor/skills/gwxapkg-ai-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gwxapkg-ai-audit" agent skill from https://github.com/25smoking/Gwxapkg/tree/main/skills/gwxapkg-ai-audit into .cursor/skills/gwxapkg-ai-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gwxapkg-ai-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/25smoking/Gwxapkg.git --path skills/gwxapkg-ai-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add 25smoking/Gwxapkg --skill gwxapkg-ai-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install 25smoking/Gwxapkg gwxapkg-ai-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/25smoking/Gwxapkg.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/gwxapkg-ai-audit .gemini/skills/gwxapkg-ai-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gwxapkg-ai-audit" agent skill from https://github.com/25smoking/Gwxapkg/tree/main/skills/gwxapkg-ai-audit into .gemini/skills/gwxapkg-ai-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gwxapkg-ai-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install 25smoking/Gwxapkg gwxapkg-ai-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add 25smoking/Gwxapkg --skill gwxapkg-ai-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/25smoking/Gwxapkg.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/gwxapkg-ai-audit .github/skills/gwxapkg-ai-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gwxapkg-ai-audit" agent skill from https://github.com/25smoking/Gwxapkg/tree/main/skills/gwxapkg-ai-audit into .github/skills/gwxapkg-ai-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gwxapkg-ai-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 25smoking/Gwxapkg --skill gwxapkg-ai-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install 25smoking/Gwxapkg gwxapkg-ai-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/25smoking/Gwxapkg.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/gwxapkg-ai-audit .opencode/skills/gwxapkg-ai-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gwxapkg-ai-audit" agent skill from https://github.com/25smoking/Gwxapkg/tree/main/skills/gwxapkg-ai-audit into .opencode/skills/gwxapkg-ai-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gwxapkg-ai-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gwxapkg-ai-auditA skill your agent uses when auditing a Gwxapkg unpacked WeChat Mini Program directory with LLM assistance; consumes .gwxapkg semantic artifacts, route maps, sensitivereport.json, and optional Burp…
Gwxapkg AI Audit is an agent skill from 25smoking/Gwxapkg. Use when auditing a Gwxapkg unpacked WeChat Mini Program directory with LLM assistance; consumes .gwxapkg semantic artifacts, route maps, sensitivereport.json, and optional Burp raw requests to produce evidence-backed security findings.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files (for example `agents/api-auth-analyzer.md`, `agents/burp-correlator.md` and `agents/business-risk-analyzer.md`).
It sits in Productivity & Automation. It works with WeChat. The repository describes itself as: 一款基于GO实现的微信小程序 wxapkg解包工具,支持自动扫描、解密、反编译,小程序安全测试。 The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1ad0186. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gwxapkg AI Audit loads about 1.4k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 298 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from 25smoking/Gwxapkg at commit 1ad0186, republished under its MIT licence (© 25smoking). 298 words, ~1,438 tokens.
.claude/skills/gwxapkg-ai-audit/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.对已经由 Gwxapkg 解包并执行过 semantic / scan 的微信小程序目录做本地静态安全审计。优先消费确定性产物,再让 LLM 做证据归纳、缺口检查、业务风险解释和报告组织。
核心目标:在以下业务漏洞面上产出更多、更准确的 findings:
Gwxapkg 已用确定性规则生成 .gwxapkg/business_surface.* 与 ai_audit 中的业务假设;LLM 负责:回溯源码、补证据、去误报、写清风险边界与修复,而不是从零扫全站关键词。
该 skill 可由 Hermes + GPT-5.5、Codex、Claude Code 等 Agent 使用。
只在授权测试、内部审计、应急分析场景使用。默认不联网、不重放请求、不验证账号密码、不编写利用代码,不修改被审计源码。
可选活体验证(需显式授权):
gwxapkg validate -dir=<dir> -base-url=https://api.example.com -i-authorize-live=true \
-token=<登录token> -token-b=<第二账号token可选> -probe-ids=1,2,othersBIZ-* 从 needs_server_validation 更新为 confirmed / false_positive / inconclusive.gwxapkg/validation_report.json 作为活体证据/path/to/output/wxappid。.gwxapkg/ 目录。gwxapkg audit -dir=<dir> -fix=true(doctor + 业务面预筛 + findings 骨架)。gwxapkg semantic -dir=<dir> / gwxapkg scan-only -dir=<dir> -format=both。auth → idor → payment → upload/share/webview/plugin 推进假设。needs_server_validation 边界;续写 ai_audit/。按顺序读取存在的文件:
.gwxapkg/business_surface.json / .md(业务面主入口).gwxapkg/ai_audit/business_hypotheses.json / business_checklist.md.gwxapkg/ai_audit/findings.json(含 BIZ-* 业务假设).gwxapkg/doctor_report.json.gwxapkg/api_unified_map.json(含 business_tags 时优先).gwxapkg/api_map.json / api_endpoint_map.json.gwxapkg/api_call_chain.json / dataflow_hints.json.gwxapkg/semantic_module_map.json / ast_rename_map.json.gwxapkg/burp_api_link.jsonroute_manifest.jsonsensitive_report.jsonsensitive_report.html 和 sensitive_report.xlsx 只作为人工复核材料,不作为 LLM 主数据源。
报告必须单独列出“覆盖缺口”,至少检查:
controllerName、动态 methodsName。sensitive_report.json 是否缺失,缺失时说明 HTML/Excel 不能作为稳定机器证据。.gwxapkg/api_map.json 为空但 .gwxapkg/api_endpoint_map.json 有数据,应明确写成“语义 API 地图覆盖不足,但通用 endpoint fallback 可用”,不要误判为没有接口证据。对 business_surface 中 已检出 的面,报告里必须有对应章节或 findings;未检出的面在 coverage 中说明「无信号/可能未实现」。
| surface | 必查点 |
|---|---|
| auth | 登录注册、短信验证码频控/一次性、重置密码、token 落 storage |
| idor | userId/orderId/证件 id 是否仅登录态无属主校验 |
| payment | 金额/优惠/积分是否前端可控、资格与状态机 |
| upload | 上传鉴权、类型限制、URL 暴露 |
| share | 分享参数篡改、绕过鉴权进入 |
| webview | src 可控、域名白名单、桥接 API |
| plugin | 插件权限与数据外传 |
优先针对 business_surface 给出的 apis/pages/files;不足时再扩大:
rg -n "controllerName|methodsName|wx\\.request|uni\\.request|request\\(" <dir>
rg -n "login|register|sendCode|verifyCode|resetPassword|getPhoneNumber" <dir>
rg -n "userId|orderId|memberId|openid|token|session|Authorization|getStorageSync|setStorageSync" <dir>
rg -n "pay|prepay|coupon|integral|point|uploadFile|onShareAppMessage|web-view|requirePlugin" <dir>
rg -n "SM2|sm2|SM4|CryptoJS|encrypt|decrypt|sign|md5" <dir>如果发现可疑 API,再用文件局部读取确认上下文,避免只凭关键词下结论。
可以按需读取 agents/ 下的角色提示词;工具支持并行时可并行分析,但最终必须统一去重和校验证据。
agents/context-reader.md:整理产物和目录上下文。agents/coverage-gap-checker.md:检查遗漏和证据缺口。agents/secret-triage.md:复核敏感信息扫描结果。agents/api-auth-analyzer.md:分析 API 鉴权、越权、IDOR。agents/crypto-dataflow-analyzer.md:分析编码、加密、签名和前端可逆逻辑。agents/business-risk-analyzer.md:分析注册、登录、验证码、重置、证照查询等业务风险。agents/burp-correlator.md:把 Burp 请求映射到源码 API。agents/reporter.md:汇总报告和 JSON findings。每个漏洞或风险项都必须包含:
id、title、severity、confidence、status、可选 validation_layerstatus 语义(必须遵守):| status | 含义 |
|---|---|
confirmed_static | 仅前端源码即可认定(如开放 WebView 无白名单) |
needs_server_validation | 源码有攻击面,结论依赖后端 |
unauth_denied | 活体:匿名被拒(≠ 无洞) |
auth_idor_untested | 活体:匿名被拒或未给 token,登录后越权未测 |
confirmed | 活体响应证实风险 |
false_positive | 在已执行探测范围内充分否定 |
inconclusive / skipped | 证据不足或策略跳过 |
禁止把 unauth_denied / auth_idor_untested 写成「已证实无漏洞」。
不要把“前端能还原参数”直接等同于“后端必然越权”;但 confirmed_static 的前端缺陷应直接写入报告。
默认输出本地授权审计报告,不做脱敏、不用 [REDACTED]、不截断关键凭据、Token、URL、参数和代码片段。证据表、findings、manifest、Markdown 报告都应保留原始值,方便复核和复现。
只有当用户明确要求“对外版”“客户版”“脱敏版”或“隐藏敏感值”时,才生成脱敏副本;脱敏副本必须另存为新文件名,不覆盖默认完整证据报告。
默认写入 <dir>/.gwxapkg/ai_audit/:
security_report.md:中文审计报告(含业务面章节)。findings.json:结构化漏洞清单(含 SECRET-* 与 BIZ-*),建议符合 schemas/finding.schema.json。business_hypotheses.json:业务假设原样(确定性)。business_checklist.md:按面必查清单。coverage_gaps.md:覆盖缺口和业务面检出情况。evidence_table.md:证据索引表。llm_audit_manifest.json:本次读取的产物、命令、模型、时间、限制说明。可以使用 templates/security_report.md 作为报告骨架。
© 25smoking, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 11 other files in skills/gwxapkg-ai-audit of 25smoking/Gwxapkg.
Open the folder on GitHubat commit 1ad0186
Gwxapkg AI Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gwxapkg AI Audit this skill25smoking/Gwxapkg | 166 | — | ~1.4k | Automated safety check: Pass | MIT | |
| She Love Me863401402/she-love-me | 931 | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Wechat Article Extractorfreestylefly/wechat-article-extractor-skill | 136 | 1 repos | ~1k | Automated safety check: Pass | None | |
| Wechat Miniprogram Builderchenjin-cmd/wechat-miniprogram-builder | 356 | — | ~634 | Automated safety check: Pass | MIT | |
| Skill Wechat PublisherZJU-REAL/Easel | 3.4k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Wechat Mp Writerth3ee9ine/wechat-claw-skill | 207 | — | ~1.4k | Automated safety check: Pass | MIT |
863401402/she-love-me
Acquire, import, and analyze WeChat or QQ chat histories, including installing supported exporters, guiding required login or contact selection, converting exports, assessing relationship dynamics…
freestylefly/wechat-article-extractor-skill
Extract metadata and content from WeChat Official Account articles.
chenjin-cmd/wechat-miniprogram-builder
This skill should be used when the user wants to build, launch, monetize, or promote a WeChat mini-program with AI (vibe coding) — including topic selection, account registration & ICP filing…
ZJU-REAL/Easel
微信公众号文章自动创作与发布工具。给定参考文章、文字或文档,自动搜索整理全网相关信息、生成图文并茂的公众号文章,并发布到微信公众号草稿箱。特别强调反 AI 检测写作。
th3ee9ine/wechat-claw-skill
微信公众号文章全自动写作与发布。从信息搜集、AI配图规划、报刊级 HTML 排版、到草稿创建和发布的完整流程。适用于 AI 日报、财经周报、深度分析、新闻资讯类文章。内置多种模板,并提供本地渲染、校验、图片规划和发布流水线脚本。
joeseesun/qiaomu-wx-video
Qiaomu skill and workflow for downloading a WeChat Channels / 视频号 video or generated live replay when the user provides a weixin.qq.com/sph share link.
Works with
Categories
A skill your agent uses when auditing a Gwxapkg unpacked WeChat Mini Program directory with LLM assistance; consumes .gwxapkg semantic artifacts, route maps, sensitivereport.json, and optional Burp…. Gwxapkg AI Audit is an agent skill from 25smoking/Gwxapkg.json, and optional Burp raw requests to produce evidence-backed security findings.
Gwxapkg AI Audit fits situations like: auditing a Gwxapkg unpacked WeChat Mini Program directory with LLM assistance; consumes .gwxapkg semantic artifacts; sensitivereport.json; optional Burp raw requests to produce evidence-backed security findings.
Run `npx skills add 25smoking/Gwxapkg --skill gwxapkg-ai-audit -a claude-code`. Or copy the skill folder (skills/gwxapkg-ai-audit in 25smoking/Gwxapkg) into .claude/skills/gwxapkg-ai-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add 25smoking/Gwxapkg --skill gwxapkg-ai-audit -a codex`. Or copy the skill folder (skills/gwxapkg-ai-audit in 25smoking/Gwxapkg) into .agents/skills/gwxapkg-ai-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 25smoking/Gwxapkg --skill gwxapkg-ai-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gwxapkg-ai-audit, .gemini/skills/gwxapkg-ai-audit, .github/skills/gwxapkg-ai-audit and .opencode/skills/gwxapkg-ai-audit in your project.
Going by SKILL.md and its folder, Gwxapkg AI Audit needs the command-line tools its instructions call (rg).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Gwxapkg AI Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Gwxapkg AI Audit: She Love Me (863401402/she-love-me, 931 stars), Wechat Article Extractor (freestylefly/wechat-article-extractor-skill, 136 stars), Wechat Miniprogram Builder (chenjin-cmd/wechat-miniprogram-builder, 356 stars) and Skill Wechat Publisher (ZJU-REAL/Easel, 3.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
25smoking (a GitHub user) maintains it in 25smoking/Gwxapkg, which has 166 GitHub stars. The repository was last updated on August 20, 2026.
Source: 25smoking/Gwxapkg on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.