thsr-timetable

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is narrowly scoped and has no malicious installer behavior, but it routes timetable queries and a long-lived JWT through a third-party CTeam/Superior APIs proxy instead of an official THSRC endpoint. That intermediary credential flow is the main risk; overall this looks more like a trust and data-routing concern than confirmed malware.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Jul 7, 2026, 03:01 AM
Package URL
pkg:socket/skills-sh/htlin222%2Fthsr-timetable-skill%2Fthsr-timetable%2F@48e53fef6d7294ccf60fe385af3e1a5d4be3f467dd45f180a249652d0b6eb319
Security Audit — socket — thsr-timetable