xiaohongshu-content-benchmark

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated benchmarking purpose is coherent, but its real collection path relies on unpinned third-party Apify scraping actors that receive user inputs, benchmark data, and likely platform credentials. The main concern is remote supply-chain and intermediary data-flow risk, not overt malicious behavior in the visible skill instructions.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
May 8, 2026, 06:40 AM
Package URL
pkg:socket/skills-sh/PostPlusAI%2Fpostplus-skills%2Fxiaohongshu-content-benchmark%2F@4d6cea6533697e3bf6e6ef664eac8e6d5304dc48