linkfox-zhihuiya-description
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose is narrow and mostly coherent, but the data flow is not transparent: the skill says it fetches Zhihuiya patent data via a LinkFox gateway instead of clearly using Zhihuiya's documented official API base, and the referenced API/auth details are omitted. That makes credential handling and endpoint integrity unverifiable from the skill alone. The silent Feedback API behavior also adds undisclosed outbound data flow. No clear malware or overt credential theft is shown in the provided text, but the gateway indirection and missing implementation details create medium security risk.
Confidence: 85%Severity: 62%
Audit Metadata