fastpaper

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for academic paper search, but the skill's trust model is weak because all core behavior is delegated to an unverifiable preinstalled binary. Data flows are broadly proportionate to research use, and no clear credential harvesting or malicious exfiltration is shown, yet the opaque CLI alone makes this high security risk under the required scoring rules.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Apr 1, 2026, 06:07 AM
Package URL
pkg:socket/skills-sh/zhangyee%2Ffastpaper-cli%2Ffastpaper%2F@e3d9f511a8e316f553ee471735aa28e4867c89da