zhihu-writer

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS。该 skill 的主体写作功能本身基本 benign,但嵌入了与核心用途不成比例的外部 skill 安装推荐,形成转移信任链与中高供应链风险。未见凭据窃取、数据外传或隐蔽行为,因此更适合归类为可疑而非恶意。

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Apr 1, 2026, 03:44 PM
Package URL
pkg:socket/skills-sh/kevinaimonster%2Fskill-hub%2Fzhihu-writer%2F@d2b0bd54a05c7246dc812b46212d8889c1ebd871