laohan-redian

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent for a news-trending aggregator, and the documented AIHOT/OpenCLI data flows look legitimate. Main risk comes from executing an unverified local `douyin-ai.js`, broad Bash permissions, and an underspecified Scrapling fallback; these make the skill higher-risk than a simple documentation-only fetcher, but there is no clear evidence of credential theft or malicious exfiltration.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/hanzhcn%2Flaohan-skills%2Flaohan-redian%2F@bbd26ee86a1ff3b4e0a2ad6817a7eeb0026a3b6f4bf65d3d6098b9bbbecaa1cd
Security Audit — socket — laohan-redian