Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md command: node script/index.js
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward AOX bridge information lookup with minor documentation and permission-scoping caveats.
Before installing, expect this skill to run a local Node script and contact the AOX public info API when invoked. It appears read-only and purpose-aligned, but users should be comfortable with the external network dependency and should only allow memory recording for non-sensitive public status results.
Referenced artifact was not completely inspected
command: node script/index.js
The skill declares command: node script/index.js, and the static analyzer detected network capability, but the manifest does not constrain allowed tools or permissions. That means the implementation may make outbound requests or use broader execution capabilities than users or reviewers can infer from the metadata, weakening least-privilege controls and increasing the blast radius if the script is compromised or behaves unexpectedly.
The manifest description is written entirely in Chinese and presents the skill's purpose in a way that assumes Chinese-language use. There is no indication that users may interact in other languages or that the Chinese-only scope is an intentional, documented regional constraint.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
#!/usr/bin/env node
const ENDPOINTS = {
AOX: 'https://api.aox.xyz/info'
}
async function readInput() {
No suspicious patterns detected.