alterlab-labarchive

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose and first-party LabArchives data flows are coherent, but the install instructions introduce a disproportionate trust problem by routing credentials through an unofficial, personal GitHub wrapper with weak provenance. This is not confirmed malware, but it is a high supply-chain risk for an AI skill handling sensitive research data and API credentials.

Confidence: 89%Severity: 80%
Audit Metadata
Analyzed At
Apr 12, 2026, 12:50 AM
Package URL
pkg:socket/skills-sh/AlterLab-IEU%2FAlterLab-Academic-Skills%2Falterlab-labarchive%2F@548f66f0491a4a8dc29c39902bee47242a5e76d1
Security Audit — socket — alterlab-labarchive