expert-douyin

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the business purpose is coherent for Douyin operations, but the skill’s effective footprint depends on multiple opaque internal tools and cross-skill delegation that are not independently verifiable. No direct malicious behavior is shown, yet unverifiable helper CLIs, delegated session handling, and autonomous publishing make the trust and execution chain too broad to treat as benign.

Confidence: 82%Severity: 76%
SecurityMEDIUM
tools/douyin-comments/SKILL.md

SUSPICIOUS:用途与“抓取抖音评论”基本一致,但认证与数据流不走官方 open API,而是依赖共享网页会话 cookie/UA/签名;再加上两个 CLI 来源不可验证,整体风险高于普通文档型技能。未见明确恶意外传或载荷执行,因此更像高风险/边界模糊的抓取工具,而非确认恶意。

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Sep 16, 2026, 02:08 PM
Package URL
pkg:socket/skills-sh/teamwiseflow%2Fxiaobei%2Fexpert-douyin%2F@2133e835d09cd0744e9cba782a2ae431f68c10c6e2c61fb93eca595280620014
Security Audit — socket — expert-douyin