chanjing-auth
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly coherent for an OAuth helper and routes data to same-brand Chanjing services, but it depends on an npm CLI whose public source provenance was not confirmed from the evidence, and it forwards refresh tokens into that CLI. This is not fundamentally incompatible with the stated purpose, but the install-trust and credential-forwarding concerns keep it above benign.
Confidence: 81%Severity: 54%
Audit Metadata