getnote-kb

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities are largely consistent with managing Get笔记 knowledge bases, and data appears to flow to official service endpoints rather than a third-party interceptor. The main concern is install/execution trust: the skill requires an external authenticated `getnote` CLI, but the exact binary and command surface are not cleanly verifiable from the evidence, creating medium supply-chain risk rather than clear malicious intent.

Confidence: 78%Severity: 52%
Audit Metadata
Analyzed At
Apr 17, 2026, 02:14 AM
Package URL
pkg:socket/skills-sh/iswalle%2Fgetnote-cli%2Fgetnote-kb%2F@b8b63aedec8a804f497f11ed5fe68842b5e9bd38