legal-writer

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is consistent with its stated purpose (legal document drafting with research + verification). It reads/writes local project files, formats and generates DOCX, and performs direct API calls to CourtListener and eCFR for research. The design is reasonable for the use case; the main security considerations are standard: protect the COURTLISTENER_API_TOKEN, avoid storing sensitive secrets in the project directory, and be cautious when installing or auto-running system packages/tools. There are no clear indicators of intentional malicious behavior (no obfuscated payloads, no command-and-control or third-party exfiltration endpoints). Overall risk is moderate because the skill performs network requests and file persistence — appropriate safeguards and secure execution context are recommended.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:37 AM
Package URL
pkg:socket/skills-sh/kortix-ai%2Fkortix-registry%2Flegal-writer%2F@15b669d5cfdfc61f0efa157d221addc16162b195