chanjing-avatar

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability fits a lip-sync API skill and the network targets appear largely same-org, but the skill embeds a hard-coded secret_key and asks the agent to use it directly. That credential handling is not proportionate for a normal public integration and creates avoidable trust and account-ownership uncertainty, even though there is no malware-like installer or third-party proxy.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Mar 14, 2026, 01:26 AM
Package URL
pkg:socket/skills-sh/chanjing-ai%2Fchan-skills%2Fchanjing-avatar%2F@4b1c92a4473956a8a991dbe0e28934f63f632603