user-docs-to-ai-skill

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches its capabilities, but it converts arbitrary external documentation into new agent-consumable skills while holding Bash/Write access and delegating workflow generation. The main concern is indirect prompt injection and transitive trust from untrusted docs, not clear malware or credential theft.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:42 AM
Package URL
pkg:socket/skills-sh/Jamie-BitFlight%2Fclaude_skills%2Fuser-docs-to-ai-skill%2F@e4ebf87829c0ca10ba29bf2b59c57c0c0c0aa3f1