triage

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core skill behavior is coherent and low-risk when it uses the official Readwise MCP/API, but the undocumented `readwise` CLI fallback weakens install trust and can expose Readwise credentials to third-party code. Purpose and scope are otherwise proportionate, so this is not confirmed malware, but it carries medium security risk unless the fallback is removed or replaced with a verified same-org client.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Mar 13, 2026, 03:10 PM
Package URL
pkg:socket/skills-sh/readwiseio%2Freadwise-skills%2Ftriage%2F@2a51c7643a2e512a85f25e7d438276db1e6fc3f0