novel-writer-cli

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该 Skill 的功能范围与“用 WPS 笔记做小说长期记忆与归档”这一目的基本一致,未见明显凭证窃取或无关敏感文件访问;但其核心执行链完全依赖无法公开验证来源与实现的 `wpsnote-cli` 黑盒工具。依据强制规则,这使整体应判为 SUSPICIOUS:不是已确认恶意,但存在较高供应链与内容外发风险。

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 21, 2026, 09:43 AM
Package URL
pkg:socket/skills-sh/wpsnote%2Fwpsnote-skills%2Fnovel-writer-cli%2F@a98867d06b1d84f6072ebcbf3c9cac482d81f48c
Security Audit — socket — novel-writer-cli