paddleocr-doc-parsing

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated OCR purpose is plausible, but the skill asks users to provide raw credentials in chat and routes documents to a user-configured API URL via unseen local scripts. With no verified official endpoint binding or script transparency, credential and document flows are insufficiently trustworthy for a benign classification.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Mar 27, 2026, 01:11 AM
Package URL
pkg:socket/skills-sh/aidenwu0209%2Fpaddleocr-skills%2Fpaddleocr-doc-parsing%2F@6cc73f721dcb9a2ff5e6229f453ee9a31acf231e