agent-mode

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose matches document automation in WPS, but the mode is high-risk because it auto-executes model-generated JavaScript and grants wildcard skill scope. There is no clear credential theft or third-party exfiltration path in the provided text, so this is not confirmed malware, but the autonomous execution footprint is broader than necessary for safe document editing.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
Jul 21, 2026, 04:55 PM
Package URL
pkg:socket/skills-sh/claude-office-skills%2Fclaude-wps-word-plugin%2Fagent-mode%2F@e611b80e6813e40fa86b63c386324ccd0a9f29c319b7f276028342b1094e0554
Security Audit — socket — agent-mode