gzh-ai-feed

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/daily_report.py

No direct malware payload (e.g., reverse shell, keylogger, cryptominer, destructive actions) is evident in the provided fragment. However, the code implements persistence (macOS LaunchAgent / Linux cron) and uses shell-based subprocess pipelines to modify scheduling. It also generates an HTML report by interpolating untrusted remote fields without escaping, which can lead to XSS when the report is opened. The local HTTP proxy returns API results and allows cross-origin access via permissive CORS. Overall, this warrants security review due to persistence and unescaped HTML injection risk.

Confidence: 64%Severity: 62%
Audit Metadata
Analyzed At
Aug 27, 2026, 07:06 AM
Package URL
pkg:socket/skills-sh/redfox-data%2Fredfox-community%2Fgzh-ai-feed%2F@d0fdbd6bb5c2eecaef4b916bda7a7f463edb0e8cd6f9afc039d965af8bd80890
Security Audit — socket — gzh-ai-feed