jupyter-notebook

Warn

Audited by Socket on Aug 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its actual footprint includes executing unverifiable third-party code from a personal GitHub repo and weakening Jupyter security by disabling auth and XSRF protections. No clear credential exfiltration is shown, but install trust and local exposure are high enough to classify as suspicious rather than benign.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Aug 14, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/nousresearch%2Fhermes-agent%2Fjupyter-notebook%2F@94e3311f2647312ecdbd0a788be56c1e23805819c4cd21165991885701addbda
Security Audit — socket — jupyter-notebook