ecommerce-chuhaijiang-tiktok-shop

Warn

Audited by Socket on Sep 14, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
scripts/chuhaijiang_seller_related_videos.py

The code appears to be a legitimate API integration with local caching and response archival, not malware. The primary security concerns are that a configurable NEXSCOPE_PROXY_BASE can receive the API key and that SESSION_ID is not sanitized before being used in filesystem paths, creating a path traversal/write-location risk when the environment is attacker-controlled. The shown fragment also appears syntactically incomplete at the final `main(` call. No evidence of credential theft beyond the intended API authorization flow, persistence, destructive behavior, or covert exfiltration is present.

Confidence: 98%Severity: 52%
AnomalyLOW
scripts/chuhaijiang_seller_rank_top_selling.py

The code appears to be a network API client with caching and local response/session persistence, not overt malware. Its primary security concern is credential disclosure to any endpoint specified by NEXSCOPE_PROXY_BASE, plus unsanitized SESSION_ID path construction that can enable path traversal when the environment is attacker-controlled. The exact supplied fragment also has a syntax error at the end. Review endpoint configuration and sanitize session identifiers before use.

Confidence: 98%Severity: 52%
AnomalyLOW
scripts/chuhaijiang_seller_search.py

The code is an API client with local caching and session-result storage. It contains no clear malware or intentional sabotage indicators. The primary security issue is unsanitized SESSION_ID path construction, which can enable path traversal and unintended file writes when the environment variable is attacker-controlled. API-key transmission to a configurable endpoint is expected behavior but should be protected by trusted environment configuration. The literal fragment also appears syntactically incomplete at the final main( call.

Confidence: 97%Severity: 56%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:15 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fecommerce-chuhaijiang-tiktok-shop%2F@4bc8bdb5cadf4ac2a7141fa37699bf28367e4e22d08fcc767333899d6d3a3e5c
Security Audit — socket — ecommerce-chuhaijiang-tiktok-shop