study

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The code fragment represents a legitimate learning workflow that downloads, parses, and organizes information from academic papers into a local knowledge base. The footprint is coherent with the stated purpose (paper study, material generation, and knowledge organization). Security concerns are modest but non-zero due to: (1) dependency installation steps that pull from external registries without visible integrity checks, (2) reliance on a download script for PDFs with no shown validation or checksum verification, and (3) potential shell/node command execution paths that could be hijacked if inputs or script sources are compromised. No credentials or secret data are evident in the provided excerpt. Overall, classify as BENIGN with MEDIUM securityRisk due to standard but non-verified dependency management and external download patterns.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 02:22 AM
Package URL
pkg:socket/skills-sh/alaliqing%2Fclaude-paper%2Fstudy%2F@8802b11ab18efcd471b1e4d3685d9da4352ada16