csdn

Warn

Audited by Socket on Aug 24, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose largely matches its capabilities, but it depends on injected full-session cookies, reverse-engineered private CSDN endpoints, and browser-fingerprint/WAF workarounds. It is not overt malware and does not show obvious third-party exfiltration, yet the credential scope and real-account posting capability make the trust boundary broader than a typical benign API integration.

Confidence: 85%Severity: 62%
AnomalyLOW
scripts/csdn.py

This module does not show clear signs of stealth malware (no dynamic execution, no persistence, no reverse shell, no system command execution, no obvious sensitive local data exfiltration). However, it has meaningful security and supply-chain risks: it embeds a hardcoded signing secret (CA_SECRET) and it performs high-impact authenticated account actions (article publication/draft creation) using user-supplied cookies. It also introduces a pathway to download and re-upload attacker-controlled external image content referenced in user Markdown. Overall risk is driven more by secret management and misuse potential than by covert malicious behavior in the snippet itself.

Confidence: 70%Severity: 52%
Audit Metadata
Analyzed At
Aug 24, 2026, 05:42 PM
Package URL
pkg:socket/skills-sh/acedatacloud%2Fskills%2Fcsdn%2F@282b0e0678c6a636fd794292bf6dd53446350089ef25afa1ac25672d1dfb0eab
Security Audit — socket — csdn