tear-sheet

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall, Report 2 presents a coherent and purpose-aligned view of a tear-sheet generator leveraging MCP data and docx-js with strong formatting enforcement. The workflow is plausible for production use, and the data path is clearly defined. However, there are notable risk signals around authentication/credential handling for MCP access, potential data leakage via intermediate files, and limited flexibility due to hard-coded formatting constraints. To improve the assessment, ensure explicit MCP credential flows, secure intermediate storage, and a mechanism to plumb audience-specific branding without sacrificing the core template integrity.

Confidence: 65%Severity: 55%
Audit Metadata
Analyzed At
Feb 25, 2026, 02:27 AM
Package URL
pkg:socket/skills-sh/anthropics%2Ffinancial-services-plugins%2Ftear-sheet%2F@03023c5e8321f5ffa5311d5826f29c01ba20bb8f