lfy-customer

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能声明用途与功能基本一致,未见明显越权、外部中转域名或直接窃密指令;但其全部能力建立在不可公开验证的 `lfy-cli` 黑盒二进制之上,且缺少安装来源与发布校验信息。整体应判为 SUSPICIOUS:不是已确认恶意,但存在高供应链与可审计性风险。

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
May 19, 2026, 07:00 AM
Package URL
pkg:socket/skills-sh/6fy%2Flfy-cli%2Flfy-customer%2F@6d3df6eafa5b3fb375d3b9d1660c372ebad36ece
Security Audit — socket — lfy-customer