moai-jit-docs-enhanced

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The provided module spec reasonably implements an intent-driven documentation loader and shows no explicit malicious code patterns (no shell execution, no obfuscated payloads, no hard-coded attacker endpoints). However, its allowed capabilities (Read, Glob, WebFetch, WebSearch) and unspecified storage/telemetry policies create a moderate privacy and supply-chain risk if implemented without safeguards. Primary risks are accidental local secrets exposure via broad file reads, leakage of contextual data via telemetry or unscoped network requests, and prompt-injection from unsanitized web content. Recommended mitigations before deployment: restrict local reads to explicit project-scoped paths and deny home directory or system-level globs by default; implement allow-lists and deny-lists for file paths; sanitize and canonicalize all fetched web content and strip executable-looking instructions; require explicit user consent for telemetry, document retention policies, and ensure caches are access-controlled and encrypted; enforce TLS verification and limit external endpoints to trusted domains when feasible. With these mitigations, the module is suitable for use; without them, treat it as a moderate security/privacy risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:10 AM
Package URL
pkg:socket/skills-sh/ajbcoding%2Fclaude-skill-eval%2Fmoai-jit-docs-enhanced%2F@90aa3dfa2ab66698e59d9867604cc8011c286c21