体彩兑奖
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill bundle is classified as suspicious due to a critical security vulnerability found in `scripts/check_lottery.py`. The script disables SSL certificate verification (`ssl.CERT_NONE` and `check_hostname = False`) when making HTTPS requests to the official lottery API (`https://webapi.sporttery.cn/gateway/lottery/getHistoryPageListV1.qry`). This exposes the communication to Man-in-the-Middle (MITM) attacks, allowing an attacker to potentially intercept and tamper with the lottery results, which could mislead the user. While this is a severe flaw, it does not show clear evidence of intentional malicious behavior like data exfiltration or system compromise.
