laohan-redian
Warn
Audited by Socket on Jun 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core purpose is coherent for a news-trending aggregator, and the documented AIHOT/OpenCLI data flows look legitimate. Main risk comes from executing an unverified local `douyin-ai.js`, broad Bash permissions, and an underspecified Scrapling fallback; these make the skill higher-risk than a simple documentation-only fetcher, but there is no clear evidence of credential theft or malicious exfiltration.
Confidence: 100%Severity: 60%
Audit Metadata