qwencloud-model-selector

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Mostly coherent as a Qwen model advisor, but the mandatory update-check workflow breaks the claimed advisory-only scope by executing local scripts and potentially installing another skill. Data flows appear limited and official, so this is better classified as suspicious overreach and transitive-trust risk rather than malware.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Mar 30, 2026, 03:05 AM
Package URL
pkg:socket/skills-sh/qwencloud%2Fqwencloud-ai%2Fqwencloud-model-selector%2F@9e654e07c556ee1e4d13e67098e9ab4ccbd0e0b3