weread

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and commands are coherent for a WeRead assistant, but it centralizes trust in a non-official external CLI that appears to come from a personal repo and may receive API keys plus private reading data. No direct malicious behavior or clear exfiltration endpoint is shown in the skill text, but the install/provenance gap and credential forwarding make this a medium-risk skill.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
May 18, 2026, 03:14 PM
Package URL
pkg:socket/skills-sh/shiquda%2Fweread-cli%2Fweread%2F@1abdc3980eac823bf820a2f1a12b889c4878144d
Security Audit — socket — weread