generate-swagger-docs

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s purpose is plausible, but its actual footprint is disproportionate. It fetches and runs an unpinned third-party script, forwards an OpenAI API key to that code, persists secrets locally, and may transmit private repository contents to undisclosed endpoints. This is high security risk even without proof of confirmed malware.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/qodex-ai%2Fai-agent-skills%2Fgenerate-swagger-docs%2F@1da5ee461b2e88f68175cfe661719473596257af