doc2qra

Fail

Audited by Socket on Mar 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
text_handler.py

The code is mainly benign text-processing utilities. The security concern is the parse_code_with_treesitter function invoking an external tool ('uvx') with a '--from' argument referencing a remote git resource and piping untrusted code into that process. This creates a supply-chain / remote-execution risk: if the external tool or the referenced repository is compromised, arbitrary code could run, and sensitive data could be exfiltrated. Recommendations: avoid automatic on-demand fetching/execution; require explicit opt-in to use external tool; validate and pin exact versions or use a vetted local parser library; sandbox or restrict the external process; validate JSON output before trusting it; add clearer error handling and logging sanitization.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:42 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fdoc2qra%2F@18923da948b81a93fa2dd57cfd6fe24bbc87d24a
Security Audit — socket — doc2qra