project-documenter

Warn

Audited by Socket on Sep 19, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The core documentation-generation behavior is coherent and there are no strong malware indicators, remote installers, or obvious credential-harvesting proxies. Risk comes from Mode 5 materially expanding scope into executable CI automation and local scripts that use API secrets without fully specifying dependencies, endpoints, or secret handling, making it broader and riskier than a simple documentation skill.

Confidence: 84%Severity: 52%
AnomalyLOW
references/mode-self-heal.md

The fragment implements a legitimate AI-assisted documentation CI system and contains no clear malicious payload, credential theft, reverse shell, cryptomining, or covert exfiltration. It does intentionally transmit repository-derived content to Anthropic/OpenAI and can automatically overwrite documentation and push commits with write permissions. Restrict workflow execution for untrusted contributions, minimize token permissions, allowlist writable documentation paths, validate AI output as a constrained patch, pin dependencies and action versions, and require review before automatic pushes.

Confidence: 98%Severity: 63%
Audit Metadata
Analyzed At
Sep 19, 2026, 10:34 AM
Package URL
pkg:socket/skills-sh/security-phoenix-demo%2Fsecurity-skills-claude-code%2Fproject-documenter%2F@f9b8089918dc4b38f3571a0610c32cc5b5ffd4778e9ba35afbc666f1c09e27ac
Security Audit — socket — project-documenter