ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      leochens

      Safety Report

      Resource 2 NAS

      @leochens

      Use when a user asks to search for movie, TV, animation, or other media resources; provides a Quark/Baidu share link to save; wants to verify saved resources...

      48Downloads
      1Installs
      0Stars
      1Versions
      Video & Audio6,897Search & Retrieval5,443

      Security Analysis

      medium confidence
      Clean0.20 risk

      This skill appears purpose-aligned, but it requires powerful cloud-drive and NAS credentials and should only be used with accounts and storage you trust it to manage.

      Jun 7, 202622 files5 concerns
      Purpose & Capabilitynote

      The stated media-to-NAS workflow matches the artifacts: search PanSou, save Quark/Baidu shares, inspect OpenList tasks, and copy saved resources to NAS/OpenList storage. These are high-impact account and storage actions, but they are disclosed and mostly preview-gated.

      Instruction Scopenote

      Implicit invocation is broad for media searches, but mutating save/copy/cancel flows instruct preview, user confirmation, and --yes before execution. Link checks and raw URL download fallbacks deserve user attention because they move private links or files through external/API workflows.

      Install Mechanismnote

      No install hooks, postinstall behavior, dependencies, or persistence setup were found. The scanned package layout has scripts/tests referring to a scripts/ directory while files are at artifact root, which is a reliability issue rather than evidence of malicious behavior.

      Credentialsnote

      The required QUARK_COOKIE, BAIDU_COOKIE, OPENLIST_TOKEN, OpenList URL, and default paths are proportionate to the advertised workflow and are repeatedly described as sensitive full credentials that should be masked and not committed.

      Persistence & Privilegenote

      No cron jobs, background workers, or hidden persistence were found. The skill can mutate cloud-drive contents, rename saved items, copy to NAS storage, and cancel OpenList tasks, but the artifacts provide confirmation gates for those operations.

      Guidance

      Before installing, treat the configured cookies and OpenList token as full account credentials. Use a dedicated or low-privilege OpenList token if possible, keep .env out of commits, avoid custom API bases/proxies unless you trust them, and require confirmation before any save, copy, cancel, raw_url download, or link-check operation involving private links.

      Latest Release

      v0.1.0

      Initial release

      More by @leochens

      Smart Web Fetch

      @Leochens · 12 stars

      Feishu Bot Connector

      0 stars

      Video Pipeline Bundle

      @Leochens · 0 stars

      Remote Disk Mount

      @Leochens · 0 stars

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Published by @leochens on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]