doc-image-agent

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core screenshot and document-illustration behavior fits the stated purpose, and the Playwright MCP install path appears to be official. Risk comes from broad browser automation over arbitrary websites, authenticated access via env credentials, processing untrusted web content with write/exec capability, and forwarding an API key to OpenRouter through a bundled script. This is not clearly malicious, but it is a medium-risk automation skill with meaningful credential and prompt-injection exposure.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 17, 2026, 12:35 PM
Package URL
pkg:socket/skills-sh/Felo-Inc%2Ffelo-skills%2Fdoc-image-agent%2F@93ae88f91b93657e0ec309ef218254a6dc0feae2