xhs-business-validator
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core TikHub research workflow is coherent with the stated purpose and uses same-service API endpoints, but the skill unnecessarily has the agent manage secrets in a workspace .env and optionally forward LLM credentials plus collected content to an arbitrary OpenAI-compatible base URL. That configurable credential/data routing is the main risk; absent that, the skill would be closer to benign.
Confidence: 90%Severity: 64%
Audit Metadata