lanhu-mcp-collaboration
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core capabilities broadly match the stated Lanhu collaboration purpose, and the documented network destinations are mostly official. However, trust is weakened because the skill is published by one party while installation directs users to a different GitHub repo and to execute local install scripts, and it relies on raw browser-cookie authentication. This looks more like a risky third-party integration than confirmed malware.
Confidence: 81%Severity: 62%
Audit Metadata