notebook

Warn

Audited by Socket on Aug 5, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/normalize.py

This code is a local file normalization/conversion utility that reads input files and writes Markdown/CSV outputs. It does not show direct malicious behavior like network exfiltration, keylogging, or obfuscated payloads. However, it can execute external commands via `subprocess.run`—either a host-discovered `markitdown` binary or arbitrary commands specified in `parsers/registry.json`—which creates a significant supply-chain/sabotage risk if those files/binaries are compromised or attacker-controlled.

Confidence: 72%Severity: 52%
Audit Metadata
Analyzed At
Aug 5, 2026, 10:24 AM
Package URL
pkg:socket/skills-sh/MichaelTarasov02%2FNotebook-Agent%2Fnotebook%2F@338d0efca1f25f2ef273d3589651f0ba1c1c92f9
Security Audit — socket — notebook