audit

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are internally coherent for a local audit workflow, and there is no sign of credential harvesting or external exfiltration. However, it relies on an unverifiable doctrine CLI/MCP dependency whose provenance was not confirmed from the evidence, so execution trust is materially unclear.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Jul 25, 2026, 01:12 PM
Package URL
pkg:socket/skills-sh/davidlee%2Fdoctrine%2Faudit%2F@285b9dcb96ec0703c590ae22a2c253fe69bc5e26f829708f95707c89ae8052ad
Security Audit — socket — audit