gzh-search-crawler

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and basic capabilities are mostly aligned, and its only declared install step is benign. The main concern is trust: article search and API keys are routed through a third-party provider (redfox.hk), the skill promotes a built-in shared key, and the actual Python script is missing so its network endpoints and local proxy behavior cannot be verified. This looks more like a medium-risk third-party API integration than confirmed malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/redfox-data%2Fredfox-community%2Fgzh-search-crawler%2F@02825a057eb92531e01588c79f5255df0e82a8118b54a0e51ec351e0ffe77204
Security Audit — socket — gzh-search-crawler