docling-converter

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the Docling Converter skill appears benign and appropriately scoped for its stated purpose: converting documents to Markdown/JSON with optional OCR. The installation sources are standard, data flows are local, and there are no credential reads, external data exfiltration, or risky third-party intermediaries evident. The only notable risk is typical supply-chain risk associated with third-party Python packages, but this is mitigated by reliance on official registries and explicit, user-driven installation steps. Overall risk remains low to moderate (securityRisk ~0.25).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 03:54 AM
Package URL
pkg:socket/skills-sh/ericgandrade%2Fclaude-superskills%2Fdocling-converter%2F@3d06af36aff67f163f2708769f290dda56f28387