douyin-similar-account

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Security
SecurityMEDIUM
query_wrapper.py

This module is a high-risk dynamic loader/launcher: it forcibly sets arguments and then executes a local Python file’s source via exec(open(...).read()) without validation. While the wrapper fragment itself shows no direct malicious action, it materially increases supply-chain attack impact by turning the contents of scripts/douyin_similar_account.py into arbitrary code execution at runtime. Review and verify the integrity and behavior of the referenced script to confirm whether any malicious activity (exfiltration, credential theft, persistence, or unwanted system/network actions) exists.

Confidence: 66%Severity: 80%
Audit Metadata
Analyzed At
Aug 20, 2026, 01:01 AM
Package URL
pkg:socket/skills-sh/redfox-data%2Fredfox-community%2Fdouyin-similar-account%2F@bba85d4c17ae78ccf8fd6d308281e70d26ab19801a89073d38189c53a41d35c5
Security Audit — socket — douyin-similar-account