Search Documentation

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This 'Search Documentation' skill is consistent with its stated purpose: it takes a user query, optionally a category and limit, and uses an internal documentation search action to retrieve and synthesize answers with citations. I found no download-execute chains, no requests for secrets or broad system permissions, and no external/untrusted endpoints. The main residual risks are platform-level: (1) trust in the internal 'search_docs' implementation and documentation corpus (if those are compromised, synthesized answers could include malicious or misleading content), and (2) processing untrusted documentation content in contexts where the agent has additional write/execute privileges could enable indirect prompt injection. Overall the code is low risk for supply-chain malware, but operators should ensure the platform search and documentation storage are secured and treat synthesized outputs as untrusted when used to trigger downstream actions.

Confidence: 65%Severity: 50%
Audit Metadata
Analyzed At
Mar 3, 2026, 11:40 AM
Package URL
pkg:socket/skills-sh/SixtySecondsApp%2Fuse60%2Fsearch-documentation%2F@96ea477026dd3fd7a906b5caf298dc289fc156b6