create-document

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior matches a document-generation skill, and the main CLI dependency (Typst) is consistent with that purpose. Risk comes from autonomous processing of untrusted local content with write/exec capability, broad tool access, and reliance on unverifiable private/local package context and opaque MCP wrappers. No clear evidence of credential theft, covert behavior, or malicious exfiltration is present, but the skill’s automation footprint is larger than a low-risk documentation helper.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
Mar 28, 2026, 11:14 PM
Package URL
pkg:socket/skills-sh/clearsmog%2Fclaude-skills%2Fcreate-document%2F@74a3f2c2f5b7e4f9a1ce58f3752876bfab62c18d