docs-from-code

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Purpose and capabilities mostly align: this is a documentation skill that reads code, generates docs, and optionally opens a PR. The main risks are third-party tool trust (Graphify), hidden dependency scope in the fallback `npm install`, and processing untrusted repositories with exec/write permissions. Overall this is not malware, but it is a medium-risk skill due to supply-chain and untrusted-content handling.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Apr 19, 2026, 08:35 AM
Package URL
pkg:socket/skills-sh/Varnan-Tech%2Fopendirectory%2Fdocs-from-code%2F@634bd40d3b76e035793e089d2f10874f772c8e20