jupyter

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No direct malicious code or obfuscated payloads were found in the provided documentation. The dominant security risk is the documented ability to execute arbitrary notebook contents via jupyter nbconvert --execute; this is an intended feature but represents a high-risk sink when notebooks are untrusted. Recommend treating execution of third-party notebooks as dangerous: inspect sources before running, execute in isolated/sandboxed environments, avoid automated run-and-clear workflows without review, and add explicit warnings and mitigations in the documentation.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:31 PM
Package URL
pkg:socket/skills-sh/openhands%2Fextensions%2Fjupyter%2F@a2ab86c37f530bef6d391a7f0df3d1d9a3296499