document-skills

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
zotero-addon-market-guide/SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its capabilities, and it does not seek credentials or obvious exfiltration. However, it promotes transitive installation of third-party Zotero add-ons from personal/third-party GitHub sources without describing provenance checks, signatures, or exact network endpoints, creating moderate supply-chain risk disproportionate to a simple guide.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 2, 2026, 02:40 PM
Package URL
pkg:socket/skills-sh/wentorai%2Fresearch-plugins%2Fdocument-skills%2F@eec90dc43909abc3944e02c94cfc1addb6ed2be7