boof

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill presents a coherent, benign local-first document processing workflow with minimal credential and permission exposure. The primary security considerations relate to whether external LLMs are used for analysis and ensuring the origin/trust of the Marker and QMD tools. If all components stay local (Marker, QMD, boof.sh) and external data transfer is avoided or user-consented, the risk remains low. If an external LLM is used by default or untrusted binaries are introduced, risk increases due to potential data exposure or supply-chain concerns.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:36 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fboof%2F@f8da09b254f15413bab55c7fc8c041aaeaca423f