1688-product-search

Warn

Audited by Socket on Sep 6, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/auth_fixed.py

No strong indicators of malware or covert data exfiltration beyond legitimate OAuth token acquisition are present in this fragment. However, the code materially increases credential exposure risk by (1) printing the access token to stdout and (2) storing access/refresh tokens and app_key in plaintext JSON on disk without permission hardening or encryption. Treat the module as security-sensitive; remove token printing and protect cache storage if used in production/CI environments.

Confidence: 72%Severity: 58%
Audit Metadata
Analyzed At
Sep 6, 2026, 04:27 PM
Package URL
pkg:socket/skills-sh/leoyeai%2Fopenclaw-master-skills%2F1688-product-search%2F@4c1004e75e365c8af93856ad49047234e560cf27af54e1d507d1f3e490d2d0a0
Security Audit — socket — 1688-product-search