reading-agent
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileThe Reading Agent skill presents a coherent, purpose-aligned tool for generating structured reading notes from academic papers. Its footprint—local file ingestion, Markdown generation, bib metadata handling, and optional parallel batch processing via Haiku—keeps data flows contained to the user’s environment. Install and execution rely on standard, reputable tools (docling, pandoc) via official package managers, which is acceptable but requires user trust in these sources for reproducibility. No credential handling, external exfiltration, or malicious data flows are evident within the described scope. Overall, the skill is BENIGN with MEDIUM-low security risk due to environment dependency considerations and the potential for batch processing to involve external Haiku services if misconfigured, but no direct unsafe data paths are described.