ecommerce-chuhaijiang-tiktok-creator

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/chuhaijiang_creator_related_lives.py

The code appears to implement a legitimate API research client with local caching and session storage. It does not show clear malware indicators or intentional obfuscation. Security concerns are present: NEXSCOPE_PROXY_BASE can redirect the API key and request data, and unsanitized SESSION_ID enables path traversal or writes outside the intended directory. The fragment also appears syntactically incomplete as provided. Restrict the proxy base to an approved HTTPS host and sanitize or reject SESSION_ID path separators, absolute paths, and traversal components.

Confidence: 98%Severity: 62%
AnomalyLOW
scripts/chuhaijiang_creator_detail.py

The code is primarily an API wrapper with local caching and session logging. No clear malware or intentional data-theft payload is present. The main security issue is unsanitized SESSION_ID path construction, which can enable writes outside the intended storage directory when the environment is attacker-controlled. A secondary concern is that NEXSCOPE_PROXY_BASE can redirect the API key and request data to an arbitrary endpoint. These risks should be fixed by validating session identifiers, constraining paths beneath the intended root, and restricting or validating the API base URL. The provided fragment is also syntactically incomplete.

Confidence: 97%Severity: 63%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:13 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fecommerce-chuhaijiang-tiktok-creator%2F@6db1b5815beda6688ac979bc01048f176b3e77a486f204c8ebd76ec3a119f51b
Security Audit — socket — ecommerce-chuhaijiang-tiktok-creator