paperbanana

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose of orchestrating PaperBanana workflows and MCP integration. Credential usage is limited to standard API key authentication for OpenRouter; data flows are to legitimate endpoints for diagram/plot generation and downstream processing. No suspicious download/install patterns or credential forwarding to unknown third parties are evident. Overall risk is low to moderate (securityRisk ~0.25–0.30) with normal credential exposure considerations due to API key use; ensure TLS, proper secret handling, and avoidance of logging keys.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 04:21 PM
Package URL
pkg:socket/skills-sh/fancive%2Fclaude-skills%2Fpaperbanana%2F@66ab6d9edc8bd0499fc628aee060c4d4fce29701