docx-review

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is functionally coherent with a docx-review workflow and does not require unnecessary credentials. However, the deployment pattern (unverifiable prebuilt binary distributed via a Homebrew tap without shown checksums/signatures) introduces notable supply-chain risk. Given the combination of legitimate capabilities and unverifiable binary distribution, the overall assessment leans toward SUSPICIOUS rather than BENIGN. If the binary provenance and integrity guarantees (checksums, signatures, or a verifiable release pathway) are provided, the risk posture could move closer to BENIGN.

Confidence: 65%Severity: 75%
Audit Metadata
Analyzed At
Mar 10, 2026, 07:13 AM
Package URL
pkg:socket/skills-sh/drpedapati%2Fsciclaw%2Fdocx-review%2F@60fbbe74f0597ac489d4a913b9196d1e98a564cd
Security Audit — socket — docx-review