clinical-reports

Warn

Audited by Socket on May 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core reporting guidance is coherent, but the skill overreaches by mandating a separate community skill for figure generation when handling sensitive clinical content. The main concern is transitive installation and unclear PHI data flow through an unpinned third-party dependency, not confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 28, 2026, 03:42 PM
Package URL
pkg:socket/skills-sh/crazymsn%2Facademic-skills%2Fclinical-reports%2F@28766f3f5da7953c82b465232e2bc2098dd40d47
Security Audit — socket — clinical-reports