legal-risk-assessment-zacharie-laik

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the legal-research purpose is coherent and official GoodLegal endpoints match the stated function, so the skill is not fundamentally malicious. However, the documented optional `npx mcp-remote` bridge and API-key-in-URL pattern create medium security risk through third-party credential forwarding and broader secret exposure; direct HTTP MCP with header auth is materially safer.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
May 16, 2026, 04:14 AM
Package URL
pkg:socket/skills-sh/lawve-ai%2Fawesome-legal-skills%2Flegal-risk-assessment-zacharie-laik%2F@6760d8769a8938940d0f760855ff22b89316cd18
Security Audit — socket — legal-risk-assessment-zacharie-laik