jupyter-notebook

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its actual footprint includes executing unverifiable third-party code from a personal GitHub repo and weakening Jupyter security by disabling auth and XSRF protections. No clear credential exfiltration is shown, but install trust and local exposure are high enough to classify as suspicious rather than benign.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Jul 30, 2026, 09:38 AM
Package URL
pkg:socket/skills-sh/nousresearch%2Fhermes-agent%2Fjupyter-notebook%2F@fa9440326467e4ea1e84915c5c1701f376fb538b615458d1e7392615ae6490d1
Security Audit — socket — jupyter-notebook