ingest-compliance-doc

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches document-ingestion capabilities, and no explicit credential theft or attacker endpoint appears. Risk comes from opaque local execution (`./run.sh`), transitive trust in multiple composed skills, URL ingestion, and undocumented storage/proof-job endpoints, which make the actual execution footprint only partially verifiable.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:40 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fingest-compliance-doc%2F@61ce7fe4efe9f97ab23cde3b5974543395cb50c7
Security Audit — socket — ingest-compliance-doc