linkfox-shopee-store-returns

Warn

Audited by Socket on Aug 17, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

该 skill 的业务能力与“Shopee 店铺退货/退款”总体一致,但核心数据流并非直连 Shopee 官方,而是通过 LinkFox developerProxy 和紫鸟代理中转;再加上依赖另一项授权 skill、自动调用反馈接口、以及默认本地落盘完整响应,使其整体更适合判为可疑而非明显恶意。主要风险在第三方代理接触业务数据与凭证上下文,而不是直接的恶意载荷。

Confidence: 84%Severity: 66%
AnomalyLOW
references/apis/accept-offer.md

The presented fragment outlines a standard proxy-based integration pattern for accept_offer, with risk primarily from credential management and data handling through the proxy and dependencies. No malicious code is evident, but credential exposure potential and reliance on external components warrant careful operational controls: strict input validation, minimal logging of sensitive fields, secure secret management, and auditing of the gateway/proxy behaviors. Overall, moderate risk, evolving with deployment practices.

Confidence: 47%Severity: 55%
Audit Metadata
Analyzed At
Aug 17, 2026, 07:03 AM
Package URL
pkg:socket/skills-sh/linkfox-ai%2Flinkfox-skills%2Flinkfox-shopee-store-returns%2F@e5bf0ed0a1f09e5175c1e38edb12d135a68efbfbe619fed7a1546586aadcb5f2
Security Audit — socket — linkfox-shopee-store-returns