paper-digest

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
paper_digest.py

The code is not overtly malicious and contains no obfuscation, command execution, persistence, or destructive behavior. It intentionally uploads the selected document and API key to a remote API and trusts a fully configurable base URL. Users should ensure the URL is trusted and HTTPS-only, because an altered URL can capture both the API key and document contents. Remote response size and content are also not constrained before local writes.

Confidence: 97%Severity: 55%
Audit Metadata
Analyzed At
Sep 16, 2026, 01:16 PM
Package URL
pkg:socket/skills-sh/somarkai%2Fskills%2Fpaper-digest%2F@b69b85c7202445acacc2b830db796342da18079805154abaef848b708fc1b088
Security Audit — socket — paper-digest