inno-rclone-to-overleaf

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose broadly matches its capabilities, and data flows target official Overleaf endpoints, but it relies on an unofficial third-party CLI that reads browser cookies/keychain data for authentication. That credential model and the ability to modify remote documents create medium risk, though there is no clear evidence of overt exfiltration or malware.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
Apr 19, 2026, 01:28 PM
Package URL
pkg:socket/skills-sh/LigphiDonk%2FOh-my--paper%2Finno-rclone-to-overleaf%2F@c114d678c72983216c64e1cac369b71af81448de