requirements-docx

Fail

Audited by Socket on Feb 24, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No direct evidence of malware, network exfiltration, or credential harvesting in the provided specification. The primary security concern is the generate-and-execute pattern combined with reading a local agent skill reference (~/.agents/skills/docx/docx-js.md), which increases the risk that a tampered local reference or input could cause arbitrary local code execution. Recommendation: require explicit user confirmation and/or sandbox the execution of generated scripts, and validate or allow inspection of reference files and the generated script prior to node execution.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 24, 2026, 05:18 AM
Package URL
pkg:socket/skills-sh/CaldiaWorks%2Fcaldiaworks-marketplace%2Frequirements-docx%2F@27e6ccf9fb52d5894cf16aea709a5decb4b2835e