paper-to-zotero

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/doi_to_item.py

The code is primarily a DOI/arXiv-to-Zotero metadata conversion and file-writing utility. No clear malware, backdoor, credential theft, shell execution, or covert exfiltration is present. A concrete security risk exists because explicit record slugs are not sanitized before being joined with the output directory; attacker-controlled input can cause path traversal or unintended file overwrite. DOI_BASE_URL and --base-url also permit routing requests to arbitrary endpoints, which should be restricted in deployments handling sensitive identifiers. The provided fragment additionally contains an incomplete `EPILOG =` assignment that causes a syntax error.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 23, 2026, 03:46 PM
Package URL
pkg:socket/skills-sh/uxfion%2Fskills%2Fpaper-to-zotero%2F@b9d943592df6eb2f16a785b6b21160f81c54eacb9219a8a8c94fc9a8410e17fb
Security Audit — socket — paper-to-zotero