doc-integrate
Audited by Socket on Feb 21, 2026
1 alert found:
Anomaly[Skill Scanner] Skill requests high-risk tools: Bash The skill is internally coherent with its stated purpose. It provides a structured, user-guided process to integrate documentation into a project repo, including metadata-driven path inference and a controlled write/update flow. No credential requirements, external network activity, or suspicious data exfiltration patterns are present. The footprint (read/write to local files, optional index updates, and user prompts) is proportionate to its documentation integration goal. LLM verification: [LLM Escalated] This skill manifest describes a repository-local document integration workflow that is consistent with its stated purpose. There is no evidence of network exfiltration, embedded credentials, obfuscated or malicious code, or download-execute supply-chain patterns. The main security considerations are: (1) the skill has permission to run Bash (broad execution power) and (2) it can overwrite repo files and update .docstore/sources.yaml, so operators must ensure user confirmation and limits on agent