oma-scholar

Warn

Audited by Socket on May 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the purpose and network destinations mostly fit scholarly sidecar workflows, but the skill’s required `oma scholar` CLI is not verifiably sourced from an official registry or same-org release trail. Because the skill may also pass an optional API key through that opaque executable, the trust gap is disproportionate and triggers high security risk despite otherwise coherent functionality.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
May 3, 2026, 01:34 AM
Package URL
pkg:socket/skills-sh/first-fluke%2Foh-my-agent%2Foma-scholar%2F@616b9a1b6050a5369ea7f60f8770f0e386b30a51