baoyu-xhs-images

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (infographic series generation for Xiaohongshu with configurable style/layout) aligns with the described workflow, inputs, and artifacts. The footprint is largely local (no unverifiable binaries, no credential handling, and no remote data exfiltration evident in the fragment). While there are multiple steps and file-system interactions, they are coherent with a developer-oriented content generation tool. Given the absence of external downloads, credential handling, or network exfiltration in the provided description, the risk remains low to moderate and within expected bounds for a tooling workflow. However, there are several areas to monitor: dependency on OpenClaw migration notes and potential prerequisites (bun, CLI tools) could introduce supply-chain risk if those tools are pulled in at runtime; ensure any such dependencies come from official registries and are pinned.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 07:52 AM
Package URL
pkg:socket/skills-sh/ideacco%2Fbaoyu-skills-openclaw%2Fbaoyu-xhs-images%2F@0ad1b3d04d8867b47fbc79d125807ad3c4b99cec