project-documentation-workflow

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the overall purpose is coherent for a documentation workflow, and its file access/write behavior is proportionate, but the actual footprint includes high-risk execution patterns. The biggest issues are shell interpolation of user input into Bash, reliance on an external CLI with only partially verified provenance, and recursive processing of untrusted repository content by spawned agents that also have write/exec capability. This looks more like a risky automation skill than confirmed malware.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
May 13, 2026, 06:40 PM
Package URL
pkg:socket/skills-sh/catlog22%2FClaude-Code-Workflow%2Fproject-documentation-workflow%2F@c4d38048f01723b6948eb1bfdedc2554434199f2
Security Audit — socket — project-documentation-workflow