doc-management

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No direct malicious code is present in the provided skill text, but it contains high-risk autonomy directives: automatic creation and automatic content retrieval without per-action user confirmation while depending on an opaque 'channel' tool that performs privileged remote actions. This combination elevates supply-chain and data-exposure risk. Recommend enforcing the L3 approval gate for create_doc, requiring explicit consent for write operations and for fetching full document contents, documenting the channel's endpoints and auth handling, and adding audit/logging and allowlist constraints before deploying in production.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 12:36 AM
Package URL
pkg:socket/skills-sh/cklxx%2Felephant.ai%2Fdoc-management%2F@083b7633d183b5e17231e5e8877eacc2268e9aff