gzh-search-crawler
Warn
Audited by Socket on Jun 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and basic capabilities are mostly aligned, and its only declared install step is benign. The main concern is trust: article search and API keys are routed through a third-party provider (redfox.hk), the skill promotes a built-in shared key, and the actual Python script is missing so its network endpoints and local proxy behavior cannot be verified. This looks more like a medium-risk third-party API integration than confirmed malware.
Confidence: 100%Severity: 60%
Audit Metadata