markdown-novel-viewer

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior is coherent for a markdown viewer, and the direct npm dependencies look normal. Risk comes from inconsistent execution scope (allowed-tools NONE vs required shell/node actions), broad arbitrary path serving, optional LAN exposure, and the recommended ClaudeKit installer path adding extra trust beyond what this skill needs.

Confidence: 83%Severity: 57%
Audit Metadata
Analyzed At
Apr 16, 2026, 02:07 PM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fmarkdown-novel-viewer%2F@68d5217f36131008ce2fdbd9adba640efb8d0bae