pixiv

Warn

Audited by Socket on Jun 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. Core Pixiv access is plausible, but the skill's actual footprint is broader than advertised: it handles account tokens, reads private account context, downloads content, and can publish posts. The largest concerns are direct refresh-token handling, third-party token-tool guidance, and autonomous posting capability rather than confirmed malware or overt exfiltration.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Jun 26, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/CraftOS-dev%2FCraftBot%2Fpixiv%2F@dfdabae6e13ac883100a712d405a181e4ab1e47ee765f3e08a524c8295dbdccf
Security Audit — socket — pixiv