nudocs

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill's documented behavior is consistent with its stated purpose: it instructs the agent to use an installed nudocs CLI to upload, list, link, pull, and delete documents on nudocs.ai and requires an API key via env var or config file. No direct malicious patterns (download-and-execute chains, obfuscated payloads, unknown exfiltration endpoints, or calls to known data-capture services) are present in the provided document. Primary risks are supply-chain trust in the external CLI package (verify publisher and repository), and the normal sensitivity of transmitting user documents and an API key to a third-party service. Verify the npm package's publisher, checksum/signature, and repository before installing; avoid uploading files containing secrets.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 11:54 AM
Package URL
pkg:socket/skills-sh/jdrhyne%2Fagent-skills%2Fnudocs%2F@de66c1503182fd304065fdd409d124760d55ab8f