share-docs

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill's described behavior is coherent with its purpose: it reads personal document directories, computes the next shared number, copies content into thoughts/shared/, updates frontmatter in both copies, and runs git add/commit/push to publish. There are no signs of supply-chain download-execute patterns, external exfiltration endpoints, or hardcoded secrets. The primary security consideration is that it performs git push (a sensitive sink) and modifies user files; these are expected for the task but should require explicit user consent and bounded retry logic to avoid accidental or repeated publication. Overall this appears benign for its intended use but operational controls (confirmation, retry limits, auditability) are recommended.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/eveld%2Fclaude%2Fshare-docs%2F@c4e3c56158eb22e5569d9474a9acf4b06c6bedd4