agent-docs-api-openapi

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This package appears to be a benign OpenAPI documentation agent that inspects repository files and edits documentation artifacts. I found no evidence of network exfiltration, hard-coded credentials, obfuscated or malicious payloads. Primary risks are operational and configuration-related: (1) hooks run shell commands starting at the repository root which could enumerate forbidden paths if the runtime does not strictly enforce allowed_paths; (2) the agent's autonomous write/edit capability allows broad automated changes and should be constrained with human review or narrower scopes; (3) malformed example placeholders could propagate into generated docs if not sanitized. Recommendations: enforce runtime enforcement of allowed_paths/forbidden_paths for hook execution, avoid starting discovery from '.', sanitize or avoid interpolating untrusted data into shell hooks, require approvals for non-trivial writes, and validate generated OpenAPI YAMLs before committing. Overall: low likelihood of deliberate malicious intent, moderate operational security risk due to autonomy and shell-hook execution.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:33 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fagent-docs-api-openapi%2F@4f1d57b1deef5ce9c42643e14c039cb07aa5ec48