build-docs
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose largely matches the capabilities, but the skill has a notable integrity problem: it ingests arbitrary remote docs from config-defined sources, uses AI to transform them into SKILL.md instructions, and then links/installs those generated skills into the agent runtime. That combination creates prompt-injection and transitive trust risk even without explicit credential theft or a malicious installer.
Confidence: 84%Severity: 68%
Audit Metadata