Legal Manager Skill

Warn

Audited by Socket on Jun 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s legal-management purpose is plausible, but its actual footprint is overbroad: it mandates autonomous handling of every received file and forces external webhook notifications containing sensitive legal summaries. The unspecified webhook destination and reliance on an unverifiable local parser materially increase risk, though the content does not show confirmed malware or overt credential theft.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Jun 1, 2026, 02:34 AM
Package URL
pkg:socket/skills-sh/casperliu7%2Fsmall-company-agent%2Flegal-manager-skill%2F@14848482a355cfb57d3499729c38e59d1f0691f5
Security Audit — socket — Legal Manager Skill