doc-sys-autopilot

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This skill document is a documentation/workflow orchestration specification for generating and validating SYS documents from ADRs. It contains no direct malicious code, network exfiltration, or credential-harvesting behavior in the supplied content. The main security concerns are operational: (1) auto-fix feature modifies repository files and should be run with caution, (2) local hooks (./hooks/*.sh) can execute arbitrary commands and must be reviewed and permissioned, and (3) the referenced transitive skills (.claude/skills/*) and CI integration expand the trust boundary and require their own review. Overall risk is moderate due to the capability to modify repository contents and run scripts in CI, not because of explicit malicious behavior in the provided files.

Confidence: 80%
Audit Metadata
Analyzed At
Mar 2, 2026, 10:20 PM
Package URL
pkg:socket/skills-sh/vladm3105%2Faidoc-flow-framework%2Fdoc-sys-autopilot%2F@63b882d29fc2854b35974636912921e97600501b