labarchive-integration

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the fragment is coherently aligned with its stated purpose of LabArchives REST API integration and automation. It describes the intended data flows and operations in a manner appropriate for legitimate integration work. Yet the explicit plaintext credential examples, configuration handling, and a questionable install command raise security concerns in practice and would require careful handling (secret management, reduced credential surface, and corrected install steps) to be considered fully secure. No evidence of malicious payloads, exfiltration, or covert actions is present in the fragment itself; it is best classified as BENIGN with MEDIUM risk due to credential exposure risk and documentation hygiene issues.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/K-Dense-AI%2Fclaude-scientific-skills%2Flabarchive-integration%2F@9220c0a60caf17570146908c90cb739e7d3c63d8