slax-reader

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The stated purpose is coherent for a bookmark-management skill, but the trust model is weak: it requires an external `reader-cli` binary whose provenance/install path could not be publicly verified, and it may receive the user's API key directly. That combination makes this suspicious and high risk from a supply-chain and credential-forwarding perspective, though there is not enough evidence to call it confirmed malware.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
May 15, 2026, 09:29 AM
Package URL
pkg:socket/skills-sh/slax-lab%2Fslax-reader-cli%2Fslax-reader%2F@4f65c62d7e64b3704fa53bb1e6577dc5918ffcc8
Security Audit — socket — slax-reader