chat-with-arxiv

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/paper_content_processor.py

The code appears to be a legitimate PDF ingestion and text-processing utility and contains no clear malware indicators. Security concerns are an unrestricted caller-controlled outbound URL, lack of response and PDF resource limits, unbounded cache growth, and missing chunk parameter validation. The URL handling should restrict schemes and destinations or use an allowlist, and resource and parameter limits should be enforced.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 19, 2026, 09:56 AM
Package URL
pkg:socket/skills-sh/qodex-ai%2Fai-agent-skills%2Fchat-with-arxiv%2F@01387addb3f4950103a5dc6e2b29e357b01981012c1a81bde434518089edaaa9
Security Audit — socket — chat-with-arxiv