maxhub-skills
Audited by Socket on Aug 2, 2026
5 alerts found:
Securityx2Anomalyx3SUSPICIOUS. The skill's query-only purpose is broadly coherent, but its real footprint routes credentials and possibly platform session cookies through a third-party domain (aconfig.cn) whose relationship to official MAXHUB developer infrastructure is unclear and inconsistent with documented MAXHUB API endpoints. No malicious payload or installer is present, but credential forwarding and mismatched service provenance create meaningful security risk.
SUSPICIOUS。该技能与“多平台数据查询聚合”描述基本一致,但核心风险在于所有凭证与请求都经由单一第三方域名 aconfig.cn 中转,且未能从公开证据充分验证其与“maxhub”发布者的官方关系或为何必须替代各平台官方 API。没有恶意下载执行迹象,因此不像明确恶意软件;但数据流与信任边界不透明,整体应视为中高风险的第三方 API 代理技能。
No direct proof of malware exists in the provided fragment because it is an API documentation/specification rather than executable source code. However, the described functionality strongly enables automated access and anti-bot evasion (fingerprinting, msToken/X-Bogus/X-Gnarly, tt_chain_token-based CDN access) and includes fraud-adjacent capabilities (play-count manipulation/fake-view analysis). The primary security concern is misuse/compliance and privacy exposure (decrypted fingerprint data), not confirmed malicious code execution in this module.
SUSPICIOUS. The skill’s stated purpose is coherent for a data-query assistant, and it does not install software or read unrelated files. However, its key and all query traffic are routed to aconfig.cn, which does not match the official MAXHUB developer endpoints or auth model cited in public docs. This makes the core data flow inconsistent and creates meaningful credential-forwarding risk through an unverifiable intermediary service.
SUSPICIOUS. The skill's analytics purpose broadly matches its Lemon8-query capabilities, and it does not use dangerous installers or hidden execution. The main issue is data-flow integrity: it routes both user queries and the MAXHUB_API_KEY to aconfig.cn, a third-party domain whose official relationship to the claimed publisher is not clearly verifiable from the provided evidence. That makes the credential routing and service provenance disproportionally opaque for an API skill.