latex-document

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core LaTeX/PDF functionality is broadly aligned with the stated purpose, but the skill is unusually expansive, performs package auto-installs, invokes a separate sibling skill, and processes untrusted external content while preserving shell/file-write capability. No clear credential theft or exfiltration is evident, so this is not malicious, but the trust and prompt-injection surface are larger than a narrowly scoped document skill.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
Apr 17, 2026, 06:25 PM
Package URL
pkg:socket/skills-sh/ndpvt-web%2Flatex-document-skill%2Flatex-document%2F@3cd9f273701c1548a6f79a8d9218477e38474c64