scientific-writing
Warn
Audited by Socket on May 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The manuscript-writing functionality is internally consistent and mostly benign, but the skill introduces an optional transitive dependency on an unverified figure-generation skill and forwards GEMINI_API_KEY to that code. Because the separate skill's provenance is not established, the optional execution path materially increases risk despite the otherwise legitimate purpose.
Confidence: 89%Severity: 81%
Audit Metadata