byted-kickart-overseas-viral-replicator

Warn

Audited by Socket on Aug 1, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent with media upload and remote video generation, and the referenced BytePlus domains appear official, but the skill requests powerful long-lived AK/SK directly, installs opaque dependencies, and routes all sensitive actions through an unseen local script. The main concern is credential forwarding and unverifiable execution trust, not confirmed malware.

Confidence: 85%Severity: 74%
AnomalyLOW
scripts/metrial.py

No strong evidence of intentionally malicious or obfuscated behavior is present in this module; it primarily implements a legitimate media upload/asset registration/search workflow. However, there are meaningful security weaknesses: the create/search API calls use plaintext HTTP (enabling MITM/tampering), and the code logs detailed request/response content including response.text, which could leak sensitive information to logs. Capability to upload arbitrary user-specified local files (by design) also increases the impact of operator misuse or repackaging, though this is not inherently malware.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Aug 1, 2026, 09:18 AM
Package URL
pkg:socket/skills-sh/bytedance%2Fagentkit-samples%2Fbyted-kickart-overseas-viral-replicator%2F@16c2e17d45e61b17909f9ee2df5592345b21e431cc8fc463d69b0bb45ead912a
Security Audit — socket — byted-kickart-overseas-viral-replicator