laohan-gengxin

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
references/tools.json

No concrete malicious payload is visible in this fragment because it is an environment dependency/update manifest rather than actual dependency/plugin source code or runtime logic. The key security concern is supply-chain and governance risk: the workflow encourages frequent updates across many ecosystems and marketplace-driven plugin/skill code replacement, and it includes stealth/scraping-capable tooling plus at least one unpinned local script. This combination increases the likelihood and impact of compromised or maliciously altered components being installed and executed later by the agent toolchain. Recommend deterministic pinning (lockfiles/hashes), provenance/signature verification for packages/plugins, and inspection/containment of stealth/scraping components and any unversioned local scripts.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 11:05 PM
Package URL
pkg:socket/skills-sh/hanzhcn%2Flaohan-skills%2Flaohan-gengxin%2F@f62905d7c486b6538f5e9e04c063556e6e62849d50e6f57c29acc8b143e2ac57
Security Audit — socket — laohan-gengxin