documenso-migration-deep-dive

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Documenso Migration Deep Dive skill is largely coherent with its stated purpose of guiding and implementing migrations to Documenso. It demonstrates reasonable scope (adapters, feature-flag rollout, data migration scaffolding, webhook normalization, rollback). The primary security concerns center on handling of API keys (secure storage and restricted access), potential data exposure through logs, and the rollout/flag endpoint's trust boundary. Overall, the footprint is benign-to-suspicious rather than malicious, with moderate risk due to credential handling and external service interactions. Mitigation should focus on secret management, access control for the feature-flag service, and safeguarding logs to prevent credential leakage.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 06:29 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fdocumenso-migration-deep-dive%2F@aab240d655e5b0f0d24da4b6852ffb5b2cbe56b6