paper2code-arxiv-implementation

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and there is no evidence of credential theft or overtly malicious data routing. However, it is installed from a third-party personal GitHub repo through a transitive skill mechanism, and it processes untrusted external paper content while generating code/files, which creates meaningful supply-chain and indirect prompt-injection risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 7, 2026, 06:55 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fpaper2code-arxiv-implementation%2F@a2031f7c34acaf6a0822d7655b4c5fce5e5b4586