labarchive-integration
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated LabArchives functionality and official API data flows are largely coherent, but it recommends installing and using an unrelated personal GitHub wrapper to handle LabArchives credentials. That third-party source install is the main risk and is disproportionate for a skill dealing with sensitive notebook data; absent the wrapper recommendation, this would be closer to benign.
Confidence: 88%Severity: 80%
Audit Metadata