Scan Report
5 /100
meitu-carousel
小红书轮播套组生成工具 - 一键生成封面+内页风格统一的轮播图组
A legitimate image carousel generation skill using meitu-cli with clear documentation, fully declared capabilities, and no malicious indicators.
Safe to install
This skill is safe to use. Consider pinning meitu-cli to a specific version in production for reproducibility.
Findings 1 items
| Severity | Finding | Location |
|---|---|---|
| Low | Unpinned npm package dependency Supply Chain | SKILL.md:22 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | READ | READ | ✓ Aligned | SKILL.md:12-14 declares file_read for credentials.json and workspace |
| Filesystem | WRITE | WRITE | ✓ Aligned | SKILL.md:13 declares file_write for workspace/visual/ |
| Shell | WRITE | WRITE | ✓ Aligned | SKILL.md:15-16 declares exec for meitu command |
File Tree
3 files · 26.3 KB · 426 lines Markdown 3f · 426L
├─
▾
references
│ ├─
memory-protocol.md
Markdown
│ └─
xiaohongshu-cover.md
Markdown
└─
SKILL.md
Markdown
Dependencies 1 items
| Package | Version | Source | Known Vulns | Notes |
|---|---|---|---|---|
meitu-cli | * | npm | No | Version not pinned |
Security Positives
✓ Comprehensive SKILL.md documentation with clear capability declarations
✓ No obfuscated code, base64 payloads, or suspicious shell patterns
✓ All credential access explicitly declared (MEITU_OPENAPI_ACCESS_KEY, MEITU_OPENAPI_SECRET_KEY)
✓ File operations scoped to specific user directories with no sensitive path access
✓ No data exfiltration or C2 communication detected
✓ Uses a legitimate commercial API (Meitu AI Open Platform)
✓ No credential harvesting beyond declared API keys
✓ Clean file tree with no binary or hidden scripts