ingest-doc

Warn

Audited by Socket on Mar 17, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
ingest_compliance.py

This Python module itself contains no obvious direct malware (no network exfiltration, no eval/obfuscation, no hard-coded secrets). However, it intentionally executes external shell scripts and conditionally imports a module from ~/.pi/skills, which creates a significant supply-chain and local code execution risk: a malicious or tampered skill script or a compromised ~/.pi/skills TaskClient can perform arbitrary harmful actions when this CLI runs. Treat the skill scripts and the ~/.pi/skills import path as untrusted inputs; verify their integrity and ownership before using this package in sensitive environments.

Confidence: 90%Severity: 60%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a document-ingestion orchestrator, and permissions are not wildly disproportionate, but the core execution path is unverifiable: ./run.sh and six composed skills are trusted without provenance, versioning, or release details. URL ingestion and ArangoDB storage are also underdocumented, leaving data-flow and transitive-trust gaps. No direct credential theft or clearly malicious endpoint is shown, so this is not confirmed malware, but it carries medium-high supply-chain and orchestration risk.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:40 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fingest-doc%2F@6bf05c2e0227d9110450157c6a8a96a421a2f212
Security Audit — socket — ingest-doc