addon-langchain-llm

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill appears purpose-aligned and proportionate: it intends to scaffold and configure LangChain-based LLM integrations across Python and Next.js ecosystems, with optional RAG and judge-evals coordination. Dependency sources are standard registries, and no obvious malicious data exfiltration or credential harvesting patterns are evident. The footprint is coherent with a developer-focused integration helper, not an autonomous agent action tool or external proxy. However, explicit data flow diagrams and sample security boundaries would strengthen assurance.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 10:41 AM
Package URL
pkg:socket/skills-sh/ajrlewis%2Fai-skills%2Faddon-langchain-llm%2F@eb805d31f66488171698f761f4af13eabaae55d2