surrealdb

Fail

Audited by Socket on Mar 15, 2026

1 alert found:

Malware
MalwareHIGH
skills/surrealfs/SKILL.md

SUSPICIOUS. The core purpose is coherent with persistent virtual filesystem operations and SurrealDB credentials, but the host command execution feature (pipe commands), remote content ingestion, optional telemetry, and HTTP agent exposure make the footprint broader and riskier than a typical filesystem abstraction. No clear evidence of malware or credential theft is present, but this is a medium-high risk skill for agent use, especially when handling untrusted prompts or content.

Confidence: 81%Severity: 68%
Audit Metadata
Analyzed At
Mar 15, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/24601%2Fsurreal-skills%2Fsurrealdb%2F@0a3b7febeaa487d107a84733e515d8e487a9d2e7