bgpt-paper-search

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align, but it expands agent trust to a third-party remote MCP service and an npm-delivered helper (`mcp-remote`). Data flow to BGPT is expected for the feature, yet the indirect routing, mixed publisher identity, and transitive external-service dependency make this medium risk rather than benign.

Confidence: 76%Severity: 56%
Audit Metadata
Analyzed At
Mar 31, 2026, 08:32 PM
Package URL
pkg:socket/skills-sh/k-dense-ai%2Fclaude-scientific-skills%2Fbgpt-paper-search%2F@6554c5b7ac542944b350c88167fea7acb92a6308