maintaining-core-documentation

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core documentation-maintenance behavior is benign and proportionate, but the mandatory recommendation to install a separate third-party skill introduces unnecessary transitive trust and supply-chain risk. No direct credential theft or exfiltration is evident, so this is not malicious, but the install workflow is inconsistent with a narrowly scoped documentation skill.

Confidence: 89%Severity: 71%
Audit Metadata
Analyzed At
May 7, 2026, 08:44 AM
Package URL
pkg:socket/skills-sh/derailed-dash%2Fdazbo-agent-skills%2Fmaintaining-core-documentation%2F@737ac01186db025b0a8c7cd914ae3325b8e42fd0