douyin-ai-feed

Warn

Audited by Socket on Aug 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core reporting behavior is mostly coherent and uses a standard PyPI dependency, but the skill routes credentials and content requests through RedFox as a third-party intermediary instead of an official Douyin API, adds recurring autonomous execution, and mandates unrelated promotional output. This is not confirmed malware, but it has medium security risk and trust concerns.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Aug 29, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/redfox-data%2Fredfox-community%2Fdouyin-ai-feed%2F@52108e6dda017c015c1ef8cceaff9ab0bcf662f4933615a054e2a65ed5a86a6c
Security Audit — socket — douyin-ai-feed