Skywork Document

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's main capabilities align with its stated purpose, but it routes user prompts, uploaded files, and auth tokens through bundled scripts to a third-party remote service, reads a cached token from the home directory, and has weaker-than-ideal distribution provenance if installed from the registry zip path. This is not clearly malicious, but it carries meaningful privacy, credential-handling, and trust risks beyond a purely local document tool.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Apr 2, 2026, 12:07 PM
Package URL
pkg:socket/skills-sh/SkyworkAI%2FSkywork-Skills%2Fskywork-document%2F@52c9ac905da429506fffcbcce1ecd74655dec831