intel-asrai

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill describes a web-search capability with a micropayment model but relies on unverifiable binaries, exposes private keys in URLs/configs, and uses external endpoints for MCP orchestration. These patterns indicate elevated supply-chain risk, credential exposure risk, and data-flow risk that are not proportionate to a benign search-as-a-service capability. Overall, the footprint is suspicious and should be treated with high scrutiny until verifiable sources, secure key handling, and safer install/promote workflows are established.

Confidence: 72%Severity: 74%
Audit Metadata
Analyzed At
Mar 8, 2026, 11:16 AM
Package URL
pkg:socket/skills-sh/abuzerasr%2Fintel-asrai-skill%2Fintel-asrai%2F@44682d51e92868ad5a769e8ed0b0b279971a0b5e