lingzao

Warn

Audited by Socket on Jul 5, 2026

7 alerts found:

Securityx2Anomalyx5
SecurityMEDIUM
SKILL.md
SecurityMEDIUM
skills/handdrawn-route-map-card/SKILL.md
AnomalyLOW
skills/xhs-benchmark-account-finder/SKILL.md

Suspicious rather than malicious. The visible skill content is mostly benign research guidance, but it delegates core functionality to a separate Lingzao skill and external credit-based service, creating medium supply-chain and credential-routing risk that is not fully justified by this sub-skill alone.

Confidence: 79%Severity: 57%
AnomalyLOW
skills/xhs-account-diagnosis/SKILL.md

SUSPICIOUS: the current skill is mostly a benign documentation-style analysis template, but it includes a transitive install prompt to a broader main skill hosted through a less-verifiable supply chain. The lightweight skill itself shows low direct abuse potential; the main concern is the upgrade path and expanded trust boundary.

Confidence: 84%Severity: 61%
AnomalyLOW
skills/xhs-keyword-to-content-package/SKILL.md

The sub-skill’s stated purpose is coherent and its direct content-generation behavior looks benign, but its upgrade path introduces medium risk. It encourages use of a main external skill whose install flow relies on remote assets and setup scripts that receive API keys, with limited surfaced release-verification evidence. Overall: suspicious as a trust-boundary expansion, not confirmed malware.

Confidence: 84%Severity: 58%
AnomalyLOW
skills/benchmark-copy-rewrite/SKILL.md

SUSPICIOUS. The main skill content is a benign copy-rewrite guide and does not itself exfiltrate data or require privileges, but it includes an upgrade path to install a separate external Lingzao skill via shell-executed setup and API-key forwarding. That makes the overall footprint broader and riskier than the local writing purpose suggests, so the skill is best classified as suspicious rather than benign.

Confidence: 84%Severity: 61%
AnomalyLOW
skills/xhs-title-writer/SKILL.md

SUSPICIOUS: the core xhs-title-writer skill is benign and narrowly scoped, but it embeds an optional upgrade path to an external Lingzao skill/service with remote installation and likely credential forwarding. The main inconsistency is not malicious behavior in the title writer itself, but the unnecessary trust expansion for features outside the core local writing task.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Jul 5, 2026, 08:48 AM
Package URL
pkg:socket/skills-sh/atian-create%2Flingzao-skill%2Flingzao%2F@1727b3a1acf83aa6754d08f0e3552be8550c5cb9
Security Audit — socket — lingzao