plotting-agent

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The plotting purpose is coherent and the local fallback scripts are proportionate, but the optional PaperBanana integration materially increases risk: it delegates execution to an unpinned external codebase and may forward a Gemini API key and paper content through third-party code with unclear provenance. No direct malicious behavior is shown, but the install/execution trust and credential-forwarding model are inconsistent with a low-risk plotting skill.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Apr 14, 2026, 02:01 PM
Package URL
pkg:socket/skills-sh/Ar9av%2FPaperOrchestra%2Fplotting-agent%2F@3c0a82f1ea2c75ccca0d267ed91a73a667369504