get-feed-detail-skill

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill conceptually aligns with retrieving feed details from an external API using a token, but there are noteworthy concerns: environment-based token handling risksCredential leakage, a mismatch between declared allowed-tools and the actual Node.js execution, and a lack of explicit security controls for network calls and data redaction. These factors place the skill in a suspicious-to-benign range, leaning toward Benign with notable security cautions that should be addressed (proper tool alignment, secure token handling, explicit TLS/endpoint safeguards, and clear data redaction policy).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 08:25 AM
Package URL
pkg:socket/skills-sh/ibreez3%2Fxiaohongshu-skill%2Fget-feed-detail-skill%2F@9515f9ab63f07f0214b201a8084ecfbcad3dfc9b