jeecg-onlchart

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability matches the stated purpose, and endpoints appear to be official Jeecg/Jeecg-adjacent services, so this is not clearly malicious. However, the skill normalizes collecting raw browser tokens and optional passwords, includes a sample that disables TLS verification, and can perform local database writes, making the security posture medium-to-high risk despite reasonable purpose alignment.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
Apr 27, 2026, 03:07 AM
Package URL
pkg:socket/skills-sh/jeecgboot%2Fskills%2Fjeecg-onlchart%2F@54240e8cfcb4e00c98955f650095f4eff76fc8df