byted-kickart-marketing-material-generator

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
references/火山鉴权指南.md

No evidence of embedded malware/backdoors or network exfiltration is present in this fragment because it is documentation/instructions rather than executable package code. However, the guide contains a severe credential-handling flaw: it explicitly instructs echoing ACCESS_KEY_ID and, critically, SECRET_ACCESS_KEY in plaintext to stdout/logs, and it also instructs users to paste SECRET_ACCESS_KEY in chat before exporting it into the environment. This creates a high likelihood of sensitive key disclosure through common logging and chat retention paths. The content should be rewritten to never print secrets and to use safer secret-management mechanisms (masked inputs, secret stores, redaction, and no echo of sensitive values).

Confidence: 82%Severity: 84%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:41 AM
Package URL
pkg:socket/skills-sh/bytedance%2Fagentkit-samples%2Fbyted-kickart-marketing-material-generator%2F@b06d2c6590c29f374a0855b217ec687b00b27368