technology-news-search

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Best-practice assessment indicates a coherent, legitimate open-source-like news-aggregation capability with dynamic routing, translation, and Markdown output. There is no evidence of credential leakage or backdoors within the fragment. Primary risk areas are privacy implications of silent network checks and potential tampering with configuration (sources.json) or the external search script. Recommend formalizing input sanitization, validating source integrity, and auditing any telemetry/logging to minimize supply-chain risk. Overall security risk is moderate; no malware detected based on the provided fragment.

Confidence: 65%Severity: 50%
Audit Metadata
Analyzed At
Mar 1, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/netease-youdao%2Flobsterai%2Ftechnology-news-search%2F@4e01bcde5858e583a0128d5ce8dc6007da929039