project-docs

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The project-docs skill is a legitimate documentation generator with expected capabilities to read project files and write documentation. I found no malicious code patterns, hard-coded credentials, or obfuscated payloads in the provided content. Primary security concerns are operational: the inclusion of a 'Bash' tool and unrestricted filesystem reads can expose secrets (e.g., .env, .npmrc) if the agent runtime has broad permissions, and there are no explicit redaction or file-scope safeguards in the templates. Recommendations: run analysis in a restricted sandbox scoped to the project directory, implement deny-listing of common secret files and redaction of sensitive values before writing or returning docs, and limit or audit Bash usage (or replace with safe high-level file inspection APIs).

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:43 PM
Package URL
pkg:socket/skills-sh/r-sri-ram%2Fbuildmvpfast-project-docs%2Fproject-docs%2F@cdb810e975db106929c019d6c97121031d886e6b