datasheet-reader

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill relies entirely on an unverified `pcb scan` binary that could not be tied to an official publisher or documented install source. It also processes arbitrary remote document content through that binary and then feeds the result to the agent, creating meaningful supply-chain and prompt-injection risk. No direct credential harvesting or explicit exfiltration is shown, so this is not confirmed malware.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/diodeinc%2Fpcb%2Fdatasheet-reader%2F@94a36d8ad9ffe23e803e9ec9d058c2f8526af2ee