meihua-yishu

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The core divination functionality is coherent, and its only package install is low-risk, but the Gemini integration is disproportionate in trust terms because it controls a live logged-in browser via Chrome DevTools Protocol instead of using a standard API. Data goes to official Google endpoints rather than a third-party proxy, so this is not confirmed malicious, but exposing remote debugging and reusing browser auth makes the skill medium risk.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/jwcodewrote%2Fagent_skills_plugin%2Fmeihua-yishu%2F@2d909c1a8c94f24a0355ef703816570ae4c7ad21