HK3 CRM 安装器
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill functions as an installer that clones a remote GitHub repository (https://github.com/jiangyisheng9-bot/hk3-crm.git) and executes its contents. The setup.sh script installs unverified Python dependencies and launches a background process (app.py) using nohup, which constitutes a remote code execution risk. While the stated purpose is a CRM installation, the reliance on an external, unverified repository to fetch and run code is a significant security concern.
