lit-synthesis

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is an academic literature-synthesis tool that integrates Zotero MCP and optional PDF-to-Markdown conversion via Docling. I found no evidence of deliberate malicious code, obfuscation, or hidden exfiltration endpoints in the provided text. The main security concerns are supply-chain and privilege risks inherent to the stated functionality: (1) requiring Zotero MCP access (sensitive credentials and full-text access), (2) unpinned pip installation of docling, (3) transitive trust in bundled skills (zotero, zotero-rag, reading-agent) and locally-run scripts whose contents are not provided. These are consistent with legitimate functionality but warrant standard mitigations: use least-privilege/API tokens scoped to specific collections, pin package versions or verify checksums, audit bundled skills and shell scripts before executing, and review git ignores to avoid committing secrets. Overall risk is moderate operational/supply-chain rather than malicious intent.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:47 AM
Package URL
pkg:socket/skills-sh/nealcaren%2Fsociology-skillset%2Flit-synthesis%2F@309f5af44479b26985796d7fdb63ce2ff24cee2b