byted-kickart-overseas-viral-replicator
Audited by Socket on Aug 1, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the stated purpose is coherent with media upload and remote video generation, and the referenced BytePlus domains appear official, but the skill requests powerful long-lived AK/SK directly, installs opaque dependencies, and routes all sensitive actions through an unseen local script. The main concern is credential forwarding and unverifiable execution trust, not confirmed malware.
No strong evidence of intentionally malicious or obfuscated behavior is present in this module; it primarily implements a legitimate media upload/asset registration/search workflow. However, there are meaningful security weaknesses: the create/search API calls use plaintext HTTP (enabling MITM/tampering), and the code logs detailed request/response content including response.text, which could leak sensitive information to logs. Capability to upload arbitrary user-specified local files (by design) also increases the impact of operator misuse or repackaging, though this is not inherently malware.