labarchive-integration
Warn
Audited by Socket on Mar 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s purpose and API data flows are coherent with LabArchives integration, and it routes data to official LabArchives endpoints. However, it relies on an unpinned third-party wrapper from an unrelated personal GitHub repo, creating disproportionate supply-chain risk for a credential-handling skill. Main concern is install trust, not confirmed malware or off-platform credential exfiltration.
Confidence: 90%Severity: 72%
Audit Metadata