docs-sync

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Purpose and capabilities are mostly aligned for a docs-impact workflow, and install/data-flow trust looks reasonable from the cited official sources. The main risk is operational: it reviews untrusted PR content while retaining shell execution and GitHub write abilities, especially if used with pull_request_target; this makes the skill medium-to-high risk but not malicious.

Confidence: 86%Severity: 69%
Audit Metadata
Analyzed At
May 16, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/microsoft%2Fapm%2Fdocs-sync%2F@b4152927afc369d9d46ea089f5a7da94c83c17a4
Security Audit — socket — docs-sync