epub

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/epub-extract-knowledge

No clear evidence of intentional malware is present in the provided code fragment. However, the LLM-backed mode creates a significant security/privacy risk: the tool sends extracted EPUB text to an externally specified HTTP endpoint and transmits an API key via an Authorization Bearer header. This is a supply-chain/integration data-exfiltration concern rather than classic malware. Confidence is reduced because the snippet appears incomplete/corrupted (missing default_prompt value and an invalid main() invocation), limiting certainty about full runtime behavior.

Confidence: 46%Severity: 58%
Audit Metadata
Analyzed At
Sep 2, 2026, 05:58 PM
Package URL
pkg:socket/skills-sh/magnus919%2Fagent-skills%2Fepub%2F@181a70af30f8cf813c37b29cde2bcaa4f6331373591d86a5f67e939c2149ab10
Security Audit — socket — epub