dev-docs-fetch

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is internally consistent: its capabilities, file reads/writes, and network calls align with the declared purpose (fetching and caching docs via Context7 MCP). It contains no download-and-execute chains, no hardcoded attacker domains, and enforces a human confirmation step before fetching. The main security consideration is trust in the configured Context7 MCP endpoints and the platform's MCP credentials/config — a compromised or malicious MCP could supply harmful content. Overall the skill appears benign for its stated use but has moderate supply-chain trust dependency on the MCP provider.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/parhumm%2Fjaan-to%2Fdev-docs-fetch%2F@787e1103e6628d491fad60b4218e3826b7f50387