baoyu-danger-x-to-markdown

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/cookies.ts

No explicit malware mechanics (e.g., remote command execution, suspicious outbound exfiltration, or obfuscated logic) are visible in this module. Nevertheless, it is security-sensitive: it harvests X/Twitter authentication cookies from a local authenticated Chrome profile using CDP, can ingest high-value tokens from environment variables and local files, may persist those secrets to disk, and constructs Cookie headers containing raw credential values. Partial token prefixes are logged, which can materially increase exposure if logs/artifacts are accessible. This should be treated as a high-impact credential-handling component and carefully reviewed in the broader project for secret handling, file permissions, logging configuration, and downstream request usage.

Confidence: 64%Severity: 68%
Audit Metadata
Analyzed At
Apr 20, 2026, 02:55 AM
Package URL
pkg:socket/skills-sh/jimliu%2Fbaoyu-skills%2Fbaoyu-danger-x-to-markdown%2F@4ac26c225a5ba22ae715c387f3d68f1a5674a7f0