inno-idea-eval

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core behavior fits its stated purpose, but it relies on an unverifiable transitive dependency in ~/.claude/skills/searching-ai-papers and ingests untrusted external content into a write-capable evaluation pipeline. No credential harvesting, exfiltration endpoint, or covert real-world action is evident, so this is better classified as a high-risk workflow dependency/prompt-surface issue than malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Sep 21, 2026, 06:00 PM
Package URL
pkg:socket/skills-sh/ligphidonk%2Foh-my--paper%2Finno-idea-eval%2F@15fecc0f938f113b2dbfef5f40582f18143a370dfbf1bd8ac8e4b2da1011d5da