huashu-nvwa

Warn

Audited by Socket on Apr 10, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
examples/sun-yuchen-perspective/SKILL.md

SUSPICIOUS. The skill is mostly a prompt-only roleplay artifact with no direct credential theft, malware behavior, or exfiltration path, but it carries medium risk because it is a transitive GitHub-hosted skill from a personal repo, uses open-web research that can import untrusted content, and is designed to produce persuasive crypto-related guidance with real-world implications.

Confidence: 86%Severity: 58%
AnomalyLOW
SKILL.md

该 Skill 的核心能力与“调研并生成人物/主题 Skill”总体一致,但其实际足迹较宽:会扫描本地 Skills、处理用户本地素材、抓取大量不可信外部内容,并把结果固化为新的 agent 指令文件。最主要风险不是直接恶意,而是供应链与间接提示注入:外部内容和第三方来源可能污染生成的 Skill,形成二次信任链。整体更适合归为可疑/中高风险的技能生成器,而非明确恶意。

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 10, 2026, 07:13 AM
Package URL
pkg:socket/skills-sh/xmg2024%2Fnvwa-skill%2Fhuashu-nvwa%2F@fdb181f0e057e837e15942707b1ea35845850979