dingtalk-docs-reader

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent with its stated purpose and routes data to official DingTalk/OSS endpoints, so it does not look malicious. However, it depends on manually extracted browser session cookies, undocumented internal APIs, and an optional TLS-disable path, creating meaningful security risk even though the capability matches the purpose.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Apr 17, 2026, 03:07 AM
Package URL
pkg:socket/skills-sh/whhe%2Fai-workshop%2Fdingtalk-docs-reader%2F@ccfcec32b6aae26da095888416758e3680f74509
Security Audit — socket — dingtalk-docs-reader