baidu-netdisk-manager

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capabilities match a Baidu Netdisk manager, but the authentication model is the main concern. Requesting raw BDUSS/STOKEN cookies, persisting login state locally, and not pointing to a clearly official documented API/auth flow make the skill riskier than a normal cloud-storage integration, even though no clear malware or overt exfiltration path is shown.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 19, 2026, 01:35 PM
Package URL
pkg:socket/skills-sh/Wscats%2Fbaidu-netdisk-skills%2Fbaidu-netdisk-manager%2F@a50d82f9b773549205857a8b7b0312e6eb4a6191