linkfox-shopee-store-payment

Warn

Audited by Socket on Aug 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/_shopee_payment_common.py

No clear malicious backdoor logic is present in this fragment (no eval/exec, no reverse shell, no obvious exfiltration to arbitrary domains). However, it does (1) execute a local neighboring script via subprocess when a dependency check fails—raising supply-chain/tampering risk—and (2) persists full gateway responses to disk, which could include sensitive Shopee store tokens or access tokens. Security risk is therefore driven by data sensitivity and subprocess execution of a locally resolved file rather than overt malware.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Aug 17, 2026, 07:03 AM
Package URL
pkg:socket/skills-sh/linkfox-ai%2Flinkfox-skills%2Flinkfox-shopee-store-payment%2F@3a16e77a0045eb252a72dc9e9d38683a637c84f90fac36b048e6b58cc0e1c848
Security Audit — socket — linkfox-shopee-store-payment