webtoon-harness

Warn

Audited by Socket on Jul 28, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but its footprint is elevated by transitive trust, multi-repo installation, shell-based scaffolding, and untrusted web-content ingestion with execution/write capabilities. No confirmed credential theft or overtly malicious behavior is shown, but the installation and delegation model make it medium-high risk.

Confidence: 83%Severity: 74%
AnomalyLOW
scripts/install.sh

No direct malware behavior is evident in the script logic itself (it only clones, copies, and optionally runs npx to install a skill). The main security concern is supply-chain trust: it fetches remote repository contents based on environment-controlled URL/ref and copies them into the consuming project’s `.claude/` directory without pinning or integrity verification; it also optionally performs an unpinned global npx install from an external repo with reduced output visibility. This warrants scrutiny of upstream sources and installation-time environment integrity.

Confidence: 70%Severity: 60%
Audit Metadata
Analyzed At
Jul 28, 2026, 01:54 PM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Fwebtoon-harness%2F@7f906a52f49c97266ab08b6293bd5ebfa0e21cab3f13be362fa47b800e9cec11
Security Audit — socket — webtoon-harness