nutrient-document-processing

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a cloud-backed document-processing integration that uploads user files and instructions to the Nutrient DWS API (https://api.nutrient.io/build) and optionally installs a provider MCP server via npx. The capabilities align with the stated purpose and there are no explicit malicious behaviors or obfuscated payloads in the provided fragment. The primary security concerns are: (1) privacy/data-exfiltration risk from sending sensitive documents to a third-party service; and (2) supply-chain risk from using npx to download and execute @nutrient-sdk/dws-mcp-server locally. Review the vendor's privacy/retention policies and audit the MCP npm package before use if you require strong supply-chain guarantees.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 03:48 PM
Package URL
pkg:socket/skills-sh/Mark393295827%2Fhouse-maint-ai%2Fnutrient-document-processing%2F@77613ea9d86fbdec0f0e66f5a278f4b39fd78b30