weibo-hub

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s Weibo-reading purpose mostly matches its capabilities, and data flows stay on first-party Weibo endpoints, but the authentication design is high-risk. It harvests browser cookies, sources an env shell file with shell=True, and stores reusable session credentials locally, while also including anti-detection scraping behavior. This is not confirmed malware, but it is a medium-risk skill with disproportionate credential handling for an agent integration.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 28, 2026, 11:49 AM
Package URL
pkg:socket/skills-sh/OpenMinis%2FMinisSkills%2Fweibo-hub%2F@a4eac13be5c45beaa4d5a24b1c6b3d3db5bb9cd6