jupyter-notebook-skills

Warn

Audited by Socket on Feb 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Download or install from free hosting/deployment platform detected No evidence of malicious code or intentional supply-chain backdoor in the provided SKILL.md. The skill is a documentation/template generator for Jupyter notebook workflows and requests only appropriate resources for its purpose (data files, ML libraries, project memory). The main security considerations are operational: users must review generated code before executing, and the MemoryStore persistence must be secured to avoid storing secrets. Overall the artifact appears benign with normal caveats about executing generated code in trusted environments. LLM verification: This SKILL.md is primarily a documentation/instruction skill for generating Jupyter notebook content and does not contain code that is directly malicious. However, there are supply-chain and privacy risks: unpinned pip install examples increase package supply-chain exposure, and the skill's use of project memory (memoryStore) could surface sensitive project data depending on its storage and access controls. The mandatory, rigid workflow language is unusual but not malicious. Overall: no evidence

Confidence: 90%Severity: 75%
Audit Metadata
Analyzed At
Feb 13, 2026, 09:45 PM
Package URL
pkg:socket/skills-sh/Olino3%2Fforge%2Fjupyter-notebook-skills%2F@c72f38200b4c7e5dc5cc9e93af159aa0b40c1200