genkit

Warn

Audited by Socket on Mar 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The Genkit manifest is broadly aligned with its intended purpose of enabling AI workflows, flows, and deployments. The primary risk arises from the remote curl|bash installer (cli.genkit.dev) lacking integrity verification, which constitutes a significant supply-chain and execution risk. While environment-based API keys and plugin-based extensibility are expected, there is a need for safer distribution mechanisms (signed installers, pinned integrity checks, or npm-based installation with package-lock) and explicit secret-management practices (scoped secrets, vault integration, rotation). Until mitigations are in place, treat the installation pathway as Suspicious with recommended hardening steps to achieve Benign status.

Confidence: 68%Severity: 65%
Audit Metadata
Analyzed At
Mar 6, 2026, 12:45 PM
Package URL
pkg:socket/skills-sh/akillness%2Fskills-template%2Fgenkit%2F@0c10a956c6a1b3c121525888fcd734a80f1c6a63