dingtalk-workflow-stock-analyzer

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能的功能与“股票研究助手”总体一致,未见明显凭证窃取或异常外传;但它依赖未验证来源的 dws CLI、具备自动定时与消息发送能力,并将外部 WebSearch 内容直接用于写表和通知。整体更像高风险可疑技能而非确认恶意,主要风险来自供应链可信度不足与自动化外部动作。

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Apr 14, 2026, 02:53 AM
Package URL
pkg:socket/skills-sh/liangdabiao%2Fdingtalk-cli-workflow%2Fdingtalk-workflow-stock-analyzer%2F@15ca6dc87e3b75c1ab0fdccfb2031376d1a1d806