api-docs

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is benign, and local file read/write access is consistent with API doc generation, but the skill’s footprint is broader than necessary. The main issue is unrestricted `npx *` execution plus a third-party MCP dispatch path, which creates avoidable supply-chain and data-flow risk without a clear need for this task.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:22 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fclaude-flow%2Fapi-docs%2F@c9e7ccee2acd19e2bbb09f4238b9f6a55c0109de2d42beae7b821a4623469422
Security Audit — socket — api-docs