node-version-compatibility-tester

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS:该技能表面上是兼容性测试器,但其核心机制是读取其他技能文档并执行其中定义的真实命令,还可能把用户凭证传给被测技能。它自身未显示明确恶意外传或伪装安装源,因此不像确认恶意软件;但作为通用跨技能执行器,存在明显的间接提示注入、凭证转交和信任链风险。

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Mar 27, 2026, 06:28 AM
Package URL
pkg:socket/skills-sh/steelan9199%2Fwechat-publisher%2Fnode-version-compatibility-tester%2F@7a4907e23e91b10a82933d3e6c819322f8dbfa74