linkfox-zhihuiya-description

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is narrow and mostly coherent, but the data flow is not transparent: the skill says it fetches Zhihuiya patent data via a LinkFox gateway instead of clearly using Zhihuiya's documented official API base, and the referenced API/auth details are omitted. That makes credential handling and endpoint integrity unverifiable from the skill alone. The silent Feedback API behavior also adds undisclosed outbound data flow. No clear malware or overt credential theft is shown in the provided text, but the gateway indirection and missing implementation details create medium security risk.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:33 AM
Package URL
pkg:socket/skills-sh/linkfox-ai%2Flinkfox-skills%2Flinkfox-zhihuiya-description%2F@2fc7f46c5bb8c791cb3dc2edc1134035f8cbcdfd