dewey-docs

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is coherent with its stated purpose: generating agent-ready documentation and scaffolding static doc sites. I found no embedded malicious code, hardcoded credentials, or explicit exfiltration paths inside the provided text. The main security concerns are general supply-chain risks from executing code installed via npx/pnpm (standard for JS tools) and an example pattern that suggests piping remote install.md into a third-party LLM (which can leak data). Overall the package appears benign in intent but carries normal package-install supply-chain risk; users should audit dependencies and avoid piping untrusted documents to remote LLM services.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 26, 2026, 01:54 AM
Package URL
pkg:socket/skills-sh/arach%2Fdewey%2Fdewey-docs%2F@4ee20f64a207f56b856f5be5f1ed24645e4d97b8