intel-asrai
Warn
Audited by Socket on Mar 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill describes a web-search capability with a micropayment model but relies on unverifiable binaries, exposes private keys in URLs/configs, and uses external endpoints for MCP orchestration. These patterns indicate elevated supply-chain risk, credential exposure risk, and data-flow risk that are not proportionate to a benign search-as-a-service capability. Overall, the footprint is suspicious and should be treated with high scrutiny until verifiable sources, secure key handling, and safer install/promote workflows are established.
Confidence: 72%Severity: 74%
Audit Metadata