document-diff

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and not overtly malicious, but it sends full document contents and the API key to a third-party service for parsing. That data flow is proportionate to the stated function yet introduces medium security risk, especially for sensitive documents and because the external service trust model is only partially verifiable from the available evidence.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 27, 2026, 09:26 AM
Package URL
pkg:socket/skills-sh/somarkai%2Fskills%2Fdocument-diff%2F@3f05267b137c6e352e27aa7ee5439bdfa15f8cf4