overleaf

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and file-sync capabilities fit Overleaf workflow, and the install paths are same-publisher and publicly documented rather than overtly malicious. However, it requires users to extract a live Overleaf session cookie from browser DevTools and hand it to a third-party CLI not operated by Overleaf, which is disproportionate and creates significant credential-forwarding risk.

Confidence: 91%Severity: 68%
Audit Metadata
Analyzed At
Sep 11, 2026, 03:19 PM
Package URL
pkg:socket/skills-sh/aloth%2Foverleaf-skill%2Foverleaf%2F@629d2f311cdea966fa51c578dceb6e01cc58e7ff
Security Audit — socket — overleaf