laohan-xiazai
Warn
Audited by Socket on Aug 27, 2026
2 alerts found:
SecurityAnomalySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS:该技能的核心用途与“互联网取内容”部分一致,但实际权限和能力明显外扩,包含技能链式安装、广泛外部 CLI 依赖、浏览器登录态接管、本地历史/书签读取,以及评论/发布等真实世界操作。OpenCLI 本身有一定同源可验证性,降低了直接恶意判断,但整体数据流、作用域和信任链都偏大,风险高于普通内容获取技能。
Confidence: 88%Severity: 79%
Anomalyreferences/other-platforms.md
LOWAnomalyLOW
references/other-platforms.md
No direct malware is evident in the supplied documentation. The principal security concern is the described MITM installation workflow: a custom root CA, privileged wrapper, automatic binary download, and lack of artifact-integrity verification create substantial interception and supply-chain risk. Assessment of actual malicious behavior requires the opencli implementation, wrapper scripts, installers, binaries, and certificate provenance.
Confidence: 96%Severity: 62%
Audit Metadata