docs-seeker
Audited by Socket on Mar 12, 2026
1 alert found:
Obfuscated FileThe skill presents a coherent, purpose-aligned workflow for discovering and analyzing documentation from multiple sources, using llms.txt-first strategies, repository analysis, and parallel exploration. The main concerns are trust and supply-chain aspects related to external domain dependencies (context7.com) and the installation of third-party tools (Repomix) without explicit verification steps. Data handling is largely read-only from public sources, with no evident credential handling, but the absence of explicit security controls (signing, verification, consent) warrants a cautious stance. Overall, the capability footprint is proportionate to its stated purpose, but the approach carries medium risk due to reliance on external sources and unverified tool installation.