lx-block
Warn
Audited by Socket on May 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s document-editing behavior is coherent and its apparent backend domains are official Lexiang/Tencent infrastructure, but it depends on an externally required `lx` CLI whose binary provenance is not publicly verifiable. Because that unverifiable CLI operates with authenticated session/token state to read and modify remote documents, the security risk is high even without direct evidence of malicious intent.
Confidence: 86%Severity: 82%
Audit Metadata