kw-skill-docs

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly a local documentation helper, but it crosses a key line by instructing the agent to derive built-in skill details from the system prompt, creating hidden-instruction disclosure risk. Aside from that, it has low operational risk: no downloads, no external endpoints, and no credential handling.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Mar 29, 2026, 04:54 PM
Package URL
pkg:socket/skills-sh/kwazema%2Fclaude-skills%2Fkw-skill-docs%2F@23be27788d7c041f6cd8e2177e74280ff95ac7b3