draft-review

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent and the skill is mostly a benign document-review workflow, but it introduces medium-risk trust issues through optional third-party OCR tooling, transitive role installation, and delegated processing of untrusted document content. No clear credential theft, exfiltration endpoint, or malicious mismatch is present in the supplied skill text.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 8, 2026, 01:00 PM
Package URL
pkg:socket/skills-sh/FuZhiyu%2FAgentContract%2Fdraft-review%2F@06ecd0f8d0459e6c1c4605716f1b74ce3b95281a