dossier-collect

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose broadly matches its capabilities, but it is overpowered for research because it combines recursive ingestion of untrusted web content with Bash, file writes, and persistent memory tools. No direct credential harvesting, remote installer, or confirmed malicious payload is present, but the prompt-injection and broad-action surface make it medium-high risk.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:22 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fclaude-flow%2Fdossier-collect%2F@517460e504909cb41d4fa5973f92f75313010a093b9e3ad043305ad9c6fb5bd8
Security Audit — socket — dossier-collect