pandoc

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The document-conversion purpose is coherent, and requested scope is narrow, but the skill’s zero-setup behavior relies on automatically downloading and executing a repackaged pandoc binary through x-cmd rather than using upstream pandoc or a standard registry/package-manager path. That creates a meaningful supply-chain trust gap without clear evidence of malicious intent.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fpandoc%2F@b049b99e0fc93bde95f8e65ab632e9143c7e250f