openevidence

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely coherent and uses official service endpoints, but it depends on raw browser session cookies and an unofficial client pattern rather than a documented auth flow. Main risk is credential exposure/forwarding from cookies.json, especially if OE_BASE_URL is overridden; supply-chain risk is low because there is no download-execute step.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 08:51 AM
Package URL
pkg:socket/skills-sh/htlin222%2Fopenevidence-skill%2Fopenevidence%2F@1bc424798540c876a1d536fae8fea8b6d48517b3
Security Audit — socket — openevidence