gemini-ocr-cli

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core OCR purpose matches the capabilities and the remote Gemini data flow is openly disclosed, but the undocumented forced secondary payload install creates a transitive trust problem. Overall this looks more like a real OCR integration with elevated supply-chain and secret-handling risk than confirmed malicious behavior.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
May 6, 2026, 10:21 AM
Package URL
pkg:socket/skills-sh/codecell-germany%2Fgemini-pdf-img-ocr-agent-skill%2Fgemini-ocr-cli%2F@29476764d301946587ef3f75b27585d7c432ae47