crawl-xueqiu-my-timeline

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core scraping/reporting behavior matches the stated purpose, but the skill combines authenticated browser-session access, analysis of untrusted social content, subagent orchestration, and unpinned third-party CLI execution via `bunx mdpdf`. This is better classified as a high-risk automation/reporting skill than outright malware: coherent in purpose, but with meaningful supply-chain and prompt-injection exposure.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
Mar 20, 2026, 05:29 AM
Package URL
pkg:socket/skills-sh/CNife%2Fmy-scripts%2Fcrawl-xueqiu-my-timeline%2F@e2b98e18bc80457ffbd3c49e6288dd039024ced7