hkr-render

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/publish.py

No clear evidence of intentional malware/backdoor in this module (no eval/exec, no persistence, no hardcoded secrets). The most notable security risk is that it will download arbitrary external images from any http/https src found in article HTML (without allowlisting) and then upload those contents to WeChat—this could enable SSRF-like behavior and unintended data movement/exfiltration if the HTML or image URLs are attacker-controlled. Overall, it appears to be a legitimate automation tool with a potentially risky network behavior.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Sep 1, 2026, 03:17 AM
Package URL
pkg:socket/skills-sh/hanzhangzzz%2Fagent-skills-zh%2Fhkr-render%2F@4df367e6f1526f8715faba4b72212ac586c7f684fc79ba2f5fd6d63b34297d6e
Security Audit — socket — hkr-render