qibook-company-profile

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent and there is no clear malware behavior, but it forwards a sensitive API key to a user-configurable `QIBOOK_BASE_URL` instead of a fixed verified official endpoint. That endpoint flexibility creates a meaningful credential and data-flow risk, keeping this above benign but below malicious.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Mar 27, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/ChinaDaaS-Department%2Fqibook-skills%2Fqibook-company-profile%2F@1f7072ff14b05e517f9f2b4ee52fdb032ea8d7f8