multi-wordcheck

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

该技能整体目的与能力基本一致:提取文本并提交外部敏感词 API 做合规检测。主要风险不在恶意执行,而在内容外传、API Key 持久化存储,以及可用环境变量把请求改道到任意网关;再加上与公开文档不一致的鉴权说明,使其更适合归类为可疑但非恶意。

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 04:14 AM
Package URL
pkg:socket/skills-sh/redfox-data%2Fredfox-community%2Fmulti-wordcheck%2F@724afa2329db055b17846b6c2c0cda9d296a77ca2963370da8eb66905328b9bb
Security Audit — socket — multi-wordcheck