ecommerce-chuhaijiang-tiktok-video

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/chuhaijiang_video_related_products.py

No clear malware or deliberate hidden exfiltration is present. The code is an API wrapper with caching and local result persistence. Security review is warranted because NEXSCOPE_PROXY_BASE can redirect the API key to any endpoint, and SESSION_ID permits path traversal in local output paths. If the final `main(` text is literal, the file also contains a syntax error. Use a trusted fixed API base and sanitize or constrain SESSION_ID before filesystem use.

Confidence: 97%Severity: 57%
AnomalyLOW
scripts/chuhaijiang_video_search.py

The code appears to be an API client with caching and local session-output management, not intentional malware. It does transmit the configured API key and request data to the configured endpoint, and it has a concrete path traversal risk through unsanitized SESSION_ID. NEXSCOPE_PROXY_BASE can also redirect credentials if an untrusted actor controls the environment. The exact supplied fragment is syntactically incomplete and would fail to run as displayed.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:14 AM
Package URL
pkg:socket/skills-sh/nexscope-ai%2Fnexscope-ecommerce-skills%2Fecommerce-chuhaijiang-tiktok-video%2F@7b34f3293888642cc471b10c1705cf8b680e171a77c6eac466162ae629ac08e8
Security Audit — socket — ecommerce-chuhaijiang-tiktok-video