markdown-novel-viewer

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core markdown-viewer behavior is largely coherent and does not show credential theft or third-party data exfiltration, but the skill serves arbitrary local paths over HTTP and supports LAN exposure via 0.0.0.0. The main trust concern is the recommended ck init bootstrap, which extends trust to a broader external CLI/install chain not necessary for this skill’s narrow purpose. Direct npm install looks lower risk than the ck path.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Apr 24, 2026, 10:23 AM
Package URL
pkg:socket/skills-sh/hiehoo%2Fforex-rebate-bot%2Fmarkdown-novel-viewer%2F@fb1effe1b70d532582977f465217b9279168c03c
Security Audit — socket — markdown-novel-viewer