document-granular-decompose
Warn
Audited by Socket on May 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s high-level purpose is coherent for remote document parsing, but it uploads local files and forwards a bearer token to an arbitrary configured host using an endpoint that does not match publicly documented official MinerU APIs. With no installer risk but unclear endpoint provenance and direct document/token forwarding, this is better classified as suspicious rather than benign.
Confidence: 88%Severity: 72%
Audit Metadata