overleaf
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and file-sync capabilities fit Overleaf workflow, and the install paths are same-publisher and publicly documented rather than overtly malicious. However, it requires users to extract a live Overleaf session cookie from browser DevTools and hand it to a third-party CLI not operated by Overleaf, which is disproportionate and creates significant credential-forwarding risk.
Confidence: 91%Severity: 68%
Audit Metadata