project-documentation-workflow

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core behavior matches a documentation workflow, but its footprint is broader than a simple local doc generator because it sends repo-wide context through an external ccw/Gemini path and then lets parallel agents with Bash/Write act on derived instructions. No clear credential theft or overt malware is present, but the combination of external analysis, broad repository ingestion, and autonomous agent execution creates medium security risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 6, 2026, 11:10 AM
Package URL
pkg:socket/skills-sh/catlog22%2FClaude-Code-Workflow%2Fproject-documentation-workflow%2F@d6e2d0b4e54380b437e2f9d8e35c216dc66ec821