tech-intel

Warn

Audited by Socket on Jun 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent with its stated purpose, but it has meaningful medium risk from third-party LLM routing via OpenRouter, sensitive Chrome-profile-based scraping, unpinned installs, and optional outbound Feishu publishing. No clear malware or deceptive exfiltration is shown, but the external data flows and credential forwarding are broader than a low-risk documentation-style skill.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Jun 22, 2026, 10:51 PM
Package URL
pkg:socket/skills-sh/xiaotonng%2Fpikiloom-skills%2Ftech-intel%2F@805ff7dbbae8a9d7adb95e1c75c38d385d960e29876700ad849ffccc8384d9ca
Security Audit — socket — tech-intel