codearts-shared

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its trust and data-flow model are not. It asks users to install a not-clearly-official CLI, store cloud AK/SK locally, and send requests through a configurable plain-HTTP gateway/IP rather than verifiable official Huawei Cloud HTTPS endpoints. That combination is disproportionate for a shared auth/bootstrap skill and creates significant credential interception risk.

Confidence: 89%Severity: 86%
Audit Metadata
Analyzed At
Apr 20, 2026, 03:18 AM
Package URL
pkg:socket/skills-sh/Lzhtommy%2Fcodearts-cli%2Fcodearts-shared%2F@b5ac1e9cd24949bbc4720f75d436a196a8eb6702