uv-read-arxiv-paper

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is coherently aligned with its stated purpose: it downloads arXiv content, extracts sources, reads/passes through the paper sections, and produces a narrative report stored locally. Data flows are restricted to local filesystem paths and standard arXiv fetches; there is no credential handling, exfiltration, or remote control. However, to improve security and reliability, implement integrity checks (hash verification) for downloaded PDFs/sources, pin script versions, and validate templates before report generation. The risk profile remains low-to-moderate and appropriate for its intended use.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 12:43 PM
Package URL
pkg:socket/skills-sh/uv-xiao%2Fpkbllm%2Fuv-read-arxiv-paper%2F@289a295f2617a3c7dc6038f2110e9c23b3f8a511