zotero-gpt-guide

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, and the GitHub release install path is plausible for a Zotero plugin, but trust is weakened by limited release-verification evidence and especially by support for arbitrary custom API endpoints that can receive both research content and API keys. This is not confirmed malware, but it carries medium security risk due to credential/data routing flexibility and release provenance concerns.

Confidence: 85%Severity: 60%
Audit Metadata
Analyzed At
Apr 7, 2026, 07:13 AM
Package URL
pkg:socket/skills-sh/wentorai%2Fresearch-plugins%2Fzotero-gpt-guide%2F@e42a20bdd4e2fba5f50760d460dd7bfa3cc20552
Security Audit — socket — zotero-gpt-guide