GraphQL Schema Documentation Builder

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is plausible, but its trust story is inconsistent: it claims GraphQL upstream provenance while installation occurs through unrelated third-party skill registries/CLIs. This is mainly a supply-chain and transitive-install risk, not confirmed malware, and there is no evidence here of credential theft or malicious data routing.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fgraphql-schema-documentation-builder%2F@8e8931d263d483ab6366082d2edd717eedde0432