project-documentation

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core documentation behavior is proportionate and benign, but the mandatory check for and optional installation of a separate third-party skill introduces unnecessary transitive trust and supply-chain risk. The main concern is not documentation editing itself, but instructing the agent to fetch and load another skill from GitHub with broad inherited permissions.

Confidence: 90%Severity: 68%
Audit Metadata
Analyzed At
Apr 11, 2026, 09:41 AM
Package URL
pkg:socket/skills-sh/derailed-dash%2Fdazbo-agent-skills%2Fproject-documentation%2F@f93edbe3854ce92e879ec2f579b13c5e34cd69d6