lx-block

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s document-editing behavior is coherent and its apparent backend domains are official Lexiang/Tencent infrastructure, but it depends on an externally required `lx` CLI whose binary provenance is not publicly verifiable. Because that unverifiable CLI operates with authenticated session/token state to read and modify remote documents, the security risk is high even without direct evidence of malicious intent.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
May 20, 2026, 09:43 PM
Package URL
pkg:socket/skills-sh/tencent-lexiang%2Flexiang-cli%2Flx-block%2F@811c76c9889293df00c6796657a375bac31c2de4
Security Audit — socket — lx-block