venue-templates

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill appears to be a legitimate template-and-workflow documentation bundle for academic venues. I found no direct evidence of malicious code, hardcoded secrets, obfuscated payloads, or explicit data-exfiltration mechanisms in the provided text. The primary security concerns are operational: helper scripts that execute local toolchains may be unsafe if implemented poorly (possible command injection or unintended shell execution), and the recommendation to use external hosted services (K-Dense Web, Nano Banana Pro / scientific-schematics) creates an avenue for users to upload unpublished or sensitive manuscripts to third-party infrastructure. Before trusting the helper scripts, inspect their source for unsafe subprocess usage and input sanitization. Before uploading work, verify the privacy and data-handling policies of any external service. Overall risk is low-to-moderate and proportional to use of external services and the exact implementations of the helper scripts.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 01:33 AM
Package URL
pkg:socket/skills-sh/jimmc414%2Fkosmos%2Fvenue-templates%2F@0802dce4f9894a11ef58faa3e8220afe7d6e83b0