surrealdb

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
skills/surrealfs/SKILL.md

SUSPICIOUS. The core purpose and official upstream relationship are broadly coherent, and the SurrealDB credentials are proportionate. However, two factors raise material risk: the unverified `pip install surrealfs-ai` install path and the explicit host command execution surface for pipe commands, which can fetch untrusted external content and write it into agent-accessible storage. Optional telemetry is disclosed but adds an extra external data flow. This looks more like a risky but plausibly legitimate skill than confirmed malware.

Confidence: 88%Severity: 66%
Audit Metadata
Analyzed At
May 7, 2026, 09:34 PM
Package URL
pkg:socket/skills-sh/24601%2Fsurreal-skills%2Fsurrealdb%2F@6daad28993a3cdf42d784df338895e2b5bf6e56b