build-docs

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose largely matches the capabilities, but the skill has a notable integrity problem: it ingests arbitrary remote docs from config-defined sources, uses AI to transform them into SKILL.md instructions, and then links/installs those generated skills into the agent runtime. That combination creates prompt-injection and transitive trust risk even without explicit credential theft or a malicious installer.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 23, 2026, 03:54 PM
Package URL
pkg:socket/skills-sh/olorehq%2Folore%2Fbuild-docs%2F@80aa9b0d6d099ac28dc558985215da0b6c9c945e