kuaishou-upload

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能目的与能力基本一致:用于快手登录与内容发布。但它把账号认证和公开发布交给未在技能内验证来源的 `sau` CLI,并允许 agent 执行真实世界的公开发帖操作,整体应判为 SUSPICIOUS 而非恶意:功能合理但权限与后果较重、外部 CLI 透明度不足。

Confidence: 79%Severity: 72%
Audit Metadata
Analyzed At
Mar 28, 2026, 03:34 AM
Package URL
pkg:socket/skills-sh/dreammis%2Fsocial-auto-upload%2Fkuaishou-upload%2F@921242563a11c2869ec6e56f0ffb71194e6f2940