ai-model-nodejs

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (Node.js CloudBase AI integration with text, streaming, and image generation) is coherent with its capabilities, installation method, and data flows. It relies on official npm packages, standard initialization patterns, and CloudBase AI endpoints. Credential handling is typical for server-side usage but should be managed securely (environment variables/secret manager). No evident risky data exfiltration, third-party binary downloads, or deceptive behaviors are present. Overall risk is low to moderate (benign) given proper secret management and adherence to least-privilege principles.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 03:50 AM
Package URL
pkg:socket/skills-sh/TencentCloudBase%2FCloudBase-AI-ToolKit%2Fai-model-nodejs%2F@6646d2c72a2319b054543551c6a01beb1133f2e5