patent-oa
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalytools/book_to_skill_setup.py
LOWAnomalyLOW
tools/book_to_skill_setup.py
The code is an installer/locator for a specific GitHub-hosted skill. It contains no clear direct malware behavior or data exfiltration, but it performs automatic execution of externally sourced npx content and can delete an existing installation directory before cloning. The primary concern is supply-chain exposure from dynamically trusted GitHub README instructions and package-manager execution. The undefined `repor` reference is a non-malicious functional bug.
Confidence: 98%Severity: 58%
Audit Metadata