markdown-novel-viewer
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core markdown-viewer behavior is largely coherent and does not show credential theft or third-party data exfiltration, but the skill serves arbitrary local paths over HTTP and supports LAN exposure via 0.0.0.0. The main trust concern is the recommended ck init bootstrap, which extends trust to a broader external CLI/install chain not necessary for this skill’s narrow purpose. Direct npm install looks lower risk than the ck path.
Confidence: 83%Severity: 56%
Audit Metadata