summary

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s overall purpose is coherent for paper summarization, and it uses official package managers rather than obviously rogue installers. However, it mixes first-run dependency installation, arbitrary remote URL fetching, local script execution, Bash+Write permissions, and a transitive call into another skill, which makes its runtime footprint broader than a minimal summarizer. No credential harvesting or clearly malicious exfiltration is visible, but the install/runtime trust and untrusted-content processing create medium security risk.

Confidence: 82%Severity: 52%
Audit Metadata
Analyzed At
Apr 9, 2026, 11:16 AM
Package URL
pkg:socket/skills-sh/alaliqing%2Fclaude-paper%2Fsummary%2F@0919694e0d8a8bc79d0ab247e0a92e5eef24bc1a