documentation-scraper

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill is functionally consistent with a documentation scraper: its capabilities, file and network access needs, and CLI usage align with the stated purpose. There is no evidence within the document of credential harvesting, obfuscated payloads, or third-party exfiltration. The primary operational risk is the repeated instruction to disable the agent sandbox (dangerouslyDisableSandbox: true) and run commands outside the sandbox — that request elevates privileges and should be treated cautiously by any agent/operator. Recommend: only run on trusted hosts, validate and audit the external `slurp` binary before installing or executing, and avoid granting broad agent-level sandbox-disabling privileges unless absolutely necessary and reviewed.

Confidence: 80%Severity: 45%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:36 PM
Package URL
pkg:socket/skills-sh/ratacat%2Fclaude-skills%2Fdocumentation-scraper%2F@2b06814e1326b51706de31e7097808bc5b327b8b