zotero-addon-market-guide

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its capabilities, and it does not seek credentials or obvious exfiltration. However, it promotes transitive installation of third-party Zotero add-ons from personal/third-party GitHub sources without describing provenance checks, signatures, or exact network endpoints, creating moderate supply-chain risk disproportionate to a simple guide.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 2, 2026, 02:41 PM
Package URL
pkg:socket/skills-sh/wentorai%2Fresearch-plugins%2Fzotero-addon-market-guide%2F@b4312e13429ad0631d7dfee99b62db64515f65bc