docx-review

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is functionally coherent with a docx-review workflow and does not require unnecessary credentials. However, the deployment pattern (unverifiable prebuilt binary distributed via a Homebrew tap without shown checksums/signatures) introduces notable supply-chain risk. Given the combination of legitimate capabilities and unverifiable binary distribution, the overall assessment leans toward SUSPICIOUS rather than BENIGN. If the binary provenance and integrity guarantees (checksums, signatures, or a verifiable release pathway) are provided, the risk posture could move closer to BENIGN.

Confidence: 65%Severity: 75%
Audit Metadata
Analyzed At
Mar 10, 2026, 07:13 AM
Package URL
pkg:socket/skills-sh/drpedapati%2Fsciclaw%2Fdocx-review%2F@60fbbe74f0597ac489d4a913b9196d1e98a564cd