laohan-xiazai

Warn

Audited by Socket on Aug 27, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS:该技能的核心用途与“互联网取内容”部分一致,但实际权限和能力明显外扩,包含技能链式安装、广泛外部 CLI 依赖、浏览器登录态接管、本地历史/书签读取,以及评论/发布等真实世界操作。OpenCLI 本身有一定同源可验证性,降低了直接恶意判断,但整体数据流、作用域和信任链都偏大,风险高于普通内容获取技能。

Confidence: 88%Severity: 79%
AnomalyLOW
references/other-platforms.md

No direct malware is evident in the supplied documentation. The principal security concern is the described MITM installation workflow: a custom root CA, privileged wrapper, automatic binary download, and lack of artifact-integrity verification create substantial interception and supply-chain risk. Assessment of actual malicious behavior requires the opencli implementation, wrapper scripts, installers, binaries, and certificate provenance.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Aug 27, 2026, 02:24 AM
Package URL
pkg:socket/skills-sh/hanzhcn%2Flaohan-skills%2Flaohan-xiazai%2F@9cc8f5ddb2910d6556dc4f25763cd7355a3e2f7ff756e024f6bab98cbcc5d6c6
Security Audit — socket — laohan-xiazai