aif-docs

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This SKILL is appropriate for its stated documentation tasks but carries moderate supply-chain and data-exfiltration risks because it permits runtime installation/execution (npx), network access (WebFetch/WebSearch), and broad filesystem reads. It includes useful guardrails (user approval, review steps) but should be implemented with concrete technical limits: pin and vet any third-party tooling, explicitly skip/redact sensitive files during scanning, and require explicit consent before sending repository contents over the network. With those mitigations in place, the skill can be used safely for generating and maintaining docs.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 12:38 AM
Package URL
pkg:socket/skills-sh/lee-to%2Fai-factory%2Faif-docs%2F@d6cbb7f5131839b343465ebe60c5f0d0fdde5591