nlm

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s notebook-management features match its stated purpose, but its trust model is weak: it relies on a non-official, ambiguous third-party `nlm` executable and obtains Google access by extracting Chrome cookies over CDP, then stores session material locally. The main concern is not overt malware but disproportionate credential handling and unverifiable external CLI trust for a Google account integration.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Mar 17, 2026, 02:36 AM
Package URL
pkg:socket/skills-sh/edwinhu%2Fworkflows%2Fnlm%2F@a81d5b524ff390d2ca90b0afec5071bfda071bfb