douyin-subscribe

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

该技能目的与主要能力基本一致:订阅抖音账号并定时生成报告。但其关键数据与API Key均流向第三方RedFoxHub而非官方抖音API,且要求Agent静默创建/更新每日自动化任务,形成中等偏高风险。未见明显恶意载荷、隐蔽下载执行或凭证文件窃取,更适合判定为SUSPICIOUS而非MALICIOUS。

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 07:58 PM
Package URL
pkg:socket/skills-sh/redfox-data%2Fredfox-community%2Fdouyin-subscribe%2F@7c7a29f0c33686985a87f5ee40c1d04dff1572e06f22c5bc019bfa87ab21ef2a
Security Audit — socket — douyin-subscribe