lfy-ops

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能的声明用途与可见命令基本一致,属于只读运营查询;但它把全部功能托付给无法公开验证来源的 `lfy-cli` 黑盒二进制,安装与执行信任不足。未见明确恶意或凭证窃取证据,因此更适合判定为可疑/高风险供应链依赖,而非确认恶意。

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 16, 2026, 01:52 AM
Package URL
pkg:socket/skills-sh/6fy%2Flfy-cli%2Flfy-ops%2F@e7a4bee85ca6055524502822e8f9bf0e5e9482f2