docusign

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is broadly coherent with its stated purpose: it uses curl-based calls to the DocuSign API, requires a valid DOCUSIGN_TOKEN, and follows documented steps to discover base_uri/account_id before performing envelope/primitives operations. The main security considerations are the handling of a sensitive API token (env var) and the temporary writing of JSON payloads to /tmp. No evidence of malicious data flows or unauthenticated third-party calls. Overall, the skill is BENIGN with MEDIUM risk due to credential exposure potential and transient local data storage; no supply-chain or exfiltration red flags identified.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fvm0-skills%2Fdocusign%2F@427a4b77d0daeadd70780642f495bcae36173c1e