dingtalk-docs-reader
Warn
Audited by Socket on Apr 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is coherent with its stated purpose and routes data to official DingTalk/OSS endpoints, so it does not look malicious. However, it depends on manually extracted browser session cookies, undocumented internal APIs, and an optional TLS-disable path, creating meaningful security risk even though the capability matches the purpose.
Confidence: 90%Severity: 56%
Audit Metadata