cookbook-audit

Warn

Audited by Socket on Feb 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [HIGH] supply_chain: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] supply_chain: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] supply_chain: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] supply_chain: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] supply_chain: Installation of third-party script detected (SC006) [AITech 9.1.4] This skill is internally consistent with its stated purpose: auditing Cookbook notebooks using a style guide and an automated validator. There are no signs of embedded malicious behaviors in the SKILL.md fragment itself. The main risk is operational: running the referenced local validator script and detect-secrets plugins without first reviewing their code could execute arbitrary actions or leak sensitive values (particularly if the environment or .env files contain secrets). Follow standard supply-chain hygiene: inspect the scripts, run in an isolated environment, and avoid exposing production secrets to the audit run. LLM verification: The skill is legitimate in intent (an audit workflow for Cookbook notebooks) and includes positive controls (detect-secrets, style guide). I found no direct malicious code or backdoors in the provided fragment. The main security concern is supply-chain and execution risk: unpinned pip installs and running custom detect-secrets plugins could lead to arbitrary code execution if an attacker compromises an upstream package or plugin. Mitigations: pin dependencies with a lockfile, vet custom plugins,

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 21, 2026, 08:06 PM
Package URL
pkg:socket/skills-sh/anthropics%2Fanthropic-cookbook%2Fcookbook-audit%2F@c722e85fd09963f877c9edb616e456cccb28963d