arkts-sta-playground

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Functionally benign as a convenience remote-compile runner, but poses a real confidentiality risk: it uploads arbitrary source code to an uncommon third-party endpoint and docs even suggest disabling SSL verification. No direct signs of malware in the provided text, yet the design is a data-exfiltration vector if the endpoint is untrusted. Validate the API operator and TLS certs before use; avoid sending sensitive code.

Confidence: 75%Severity: 55%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:26 AM
Package URL
pkg:socket/skills-sh/openharmonyinsight%2Fopenharmony-skills%2Farkts-sta-playground%2F@c807802969d37b2a7d678880b1a620dffdb8b2e7