docs-from-code

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Purpose and capabilities mostly align: this is a documentation skill that reads code, generates docs, and optionally opens a PR. The main risks are third-party tool trust (Graphify), hidden dependency scope in the fallback `npm install`, and processing untrusted repositories with exec/write permissions. Overall this is not malware, but it is a medium-risk skill due to supply-chain and untrusted-content handling.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
May 8, 2026, 03:08 PM
Package URL
pkg:socket/skills-sh/Varnan-Tech%2Fopendirectory%2Fdocs-from-code%2F@9c4761c30ed268d52a531e0fffaf211acd6e5296
Security Audit — socket — docs-from-code