alterlab-labarchive
Warn
Audited by Socket on Apr 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core purpose and first-party LabArchives data flows are coherent, but the install instructions introduce a disproportionate trust problem by routing credentials through an unofficial, personal GitHub wrapper with weak provenance. This is not confirmed malware, but it is a high supply-chain risk for an AI skill handling sensitive research data and API credentials.
Confidence: 89%Severity: 80%
Audit Metadata