mhr-cfw-domain-fronting-relay
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is internally consistent as a domain-fronting relay, but its footprint is high-risk for an AI agent skill. It installs from a third-party personal repo, offers a third-party trusted mirror, routes all traffic through intermediary services, and permits disabled TLS verification. This looks more like a censorship-bypass proxy guide than overt malware, but the install trust and traffic interception profile are disproportionate enough to classify as suspicious rather than benign.
Confidence: 89%Severity: 78%
Audit Metadata