taxue

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能本身主要是本地路由与提示编排,未见外部下载、远程安装、凭据收集或明显数据外传,恶意意图证据不足。但它要求执行一个来源不可验证的本地 Python 脚本,并依赖多个未展开的子技能,实际能力边界不透明。整体更像可疑/高风险的编排层,而非确认恶意。

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 9, 2026, 06:31 PM
Package URL
pkg:socket/skills-sh/taxueseek%2Ftaxueskills%2Ftaxue%2F@c1bc66c4434797b3115a664bb6f0651645161de0