pixiv
Warn
Audited by Socket on Jun 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. Core Pixiv access is plausible, but the skill's actual footprint is broader than advertised: it handles account tokens, reads private account context, downloads content, and can publish posts. The largest concerns are direct refresh-token handling, third-party token-tool guidance, and autonomous posting capability rather than confirmed malware or overt exfiltration.
Confidence: 84%Severity: 62%
Audit Metadata