doc-integrate

Warn

Audited by Socket on Feb 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

[Skill Scanner] Skill requests high-risk tools: Bash The skill is internally coherent with its stated purpose. It provides a structured, user-guided process to integrate documentation into a project repo, including metadata-driven path inference and a controlled write/update flow. No credential requirements, external network activity, or suspicious data exfiltration patterns are present. The footprint (read/write to local files, optional index updates, and user prompts) is proportionate to its documentation integration goal. LLM verification: [LLM Escalated] This skill manifest describes a repository-local document integration workflow that is consistent with its stated purpose. There is no evidence of network exfiltration, embedded credentials, obfuscated or malicious code, or download-execute supply-chain patterns. The main security considerations are: (1) the skill has permission to run Bash (broad execution power) and (2) it can overwrite repo files and update .docstore/sources.yaml, so operators must ensure user confirmation and limits on agent

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Feb 21, 2026, 03:29 PM
Package URL
pkg:socket/skills-sh/stanah%2Fdotagents%2Fdoc-integrate%2F@a56e1a5ed96a408fb13d5d3d8aba54d74db931ba