baoyu-danger-x-to-markdown

Warn

Audited by Socket on Jun 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/cookies.ts

No explicit malware mechanics (e.g., remote command execution, suspicious outbound exfiltration, or obfuscated logic) are visible in this module. Nevertheless, it is security-sensitive: it harvests X/Twitter authentication cookies from a local authenticated Chrome profile using CDP, can ingest high-value tokens from environment variables and local files, may persist those secrets to disk, and constructs Cookie headers containing raw credential values. Partial token prefixes are logged, which can materially increase exposure if logs/artifacts are accessible. This should be treated as a high-impact credential-handling component and carefully reviewed in the broader project for secret handling, file permissions, logging configuration, and downstream request usage.

Confidence: 64%Severity: 68%
Audit Metadata
Analyzed At
Jun 26, 2026, 08:18 AM
Package URL
pkg:socket/skills-sh/guanyang%2Fopen-agent-hub%2Fbaoyu-danger-x-to-markdown%2F@cb19b2ebbefd545c3282cd04203ca5e7d0cf1ec038b42989b72d991432883265
Security Audit — socket — baoyu-danger-x-to-markdown