using-axiv-cli
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow is mostly well-scoped for alphaXiv research and library management, but trust is undermined by the unclear `axiv` vs `alphaxiv` identity and unverifiable publisher relationship. Because authenticated operations are forced through that CLI, the main concern is supply-chain and credential-forwarding risk rather than confirmed malicious behavior.
Confidence: 84%Severity: 78%
Audit Metadata