byted-viking-cli

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS。技能目的与能力总体一致,且安装域名与官方文档可对应,未见明显第三方凭据中转;但它依赖 curl|bash 安装一个缺少公开可验证发行链路的外部 CLI,并将 AK/SK/API Key 与本地文件内容交给该 CLI,带来明显供应链与凭据暴露风险。

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:42 AM
Package URL
pkg:socket/skills-sh/bytedance%2Fagentkit-samples%2Fbyted-viking-cli%2F@dca817be0393de3b9a6744bbba67c854f45055ee
Security Audit — socket — byted-viking-cli