vendor-agreement-review

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core legal-review behavior is coherent and largely proportionate, with good user-confirmation gates for external actions. The main risk is not overt malware but unverifiable transitive trust: the skill delegates to other skills and remote MCP integrations without specifying the exact servers, publishers, or data endpoints that will receive privileged legal content.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 13, 2026, 12:41 AM
Package URL
pkg:socket/skills-sh/anthropics%2Fclaude-for-legal%2Fvendor-agreement-review%2F@fa8797b77073b7addc6cbac769e5185845f5c743