story-short-scan

Warn

Audited by Socket on Aug 24, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

该技能总体目的与“短篇榜单扫描/市场分析”基本一致,但黑岩采集通过浏览器登录态提取 Bearer token 并调用后端 API,权限与数据敏感度明显上升。未见明确恶意外传或第三方凭据中转,更像高权限抓取型分析技能;应视为中等风险而非恶意。

Confidence: 81%Severity: 56%
AnomalyLOW
scripts/cdp-utils.js

No direct evidence of overt malicious behavior (e.g., network exfiltration, persistence, credential theft) exists in this fragment. However, the module intentionally provides an “eval” channel by base64-encoding and forwarding caller-provided JavaScript to a spawned agent-browser, creating a high-impact execution primitive if inputs are not strictly trusted. On Windows, it also resolves execution via PATH-discovered agent-browser.cmd contents, increasing the risk of executing a substituted/malicious wrapper in compromised environments. Treat this module as security-sensitive and enforce strict trust boundaries on js/args and on PATH/executable resolution.

Confidence: 63%Severity: 62%
Audit Metadata
Analyzed At
Aug 24, 2026, 03:18 PM
Package URL
pkg:socket/skills-sh/zenstory-ai%2Foh-story-claudecode%2Fstory-short-scan%2F@b243f127aa686ccf56124f0b687fe849ca8c685430890dfc986c913e289e7f66
Security Audit — socket — story-short-scan