audit

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent for a local audit workflow and it does not explicitly request secrets or exfiltrate data, but it materially depends on a `doctrine` CLI/MCP toolchain whose provenance could not be verified from the provided evidence. That unverifiable execution dependency makes the skill high-risk from a supply-chain standpoint even though the skill text itself is not overtly malicious.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Aug 1, 2026, 02:08 PM
Package URL
pkg:socket/skills-sh/davidlee%2Fdoctrine%2Faudit%2F@aeaec28dbb12a749fb0cedbe80d96284197002c892be80b215330d26377cfddb
Security Audit — socket — audit