asta-documents

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior largely matches its stated document-management purpose, and the primary installer appears same-org and version-pinned. However, repo inconsistency, remote index ingestion from arbitrary decoded URLs, optional cloud-credential use, and untrusted-content fetching with Bash/Read capabilities create meaningful medium risk beyond a simple local bookmark index.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 11, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/allenai%2Fasta-plugins%2Fasta-documents%2F@69063680242c707a599913a74dc91725b561cd5c