cultural-tourism-wechat-feed

Warn

Audited by Socket on Aug 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/cultural_tourism_report.py

The visible code primarily implements an API-backed reporting utility. It does not show clear malware behavior, obfuscated payloads, credential theft beyond intentional use of a configured API key, or destructive activity. It contains meaningful security issues: unescaped API data in generated HTML can enable report-based HTML injection and unintended browser requests, and shell=True with interpolated subscription values creates a command-injection risk. Scheduled-task persistence is user-facing functionality rather than inherently malicious behavior. The incomplete/corrupted fragment prevents a complete review of the missing functions.

Confidence: 94%Severity: 62%
Audit Metadata
Analyzed At
Aug 29, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/redfox-data%2Fredfox-community%2Fcultural-tourism-wechat-feed%2F@1a832c2353f970e37ba2a59499c82706807d2beab891bc57d25cc80fb4307b15
Security Audit — socket — cultural-tourism-wechat-feed