langchain
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill description and content align coherently with its stated purpose: a LangChain-based framework for composing LLM-powered workflows using chains, tools, and agents. The install path uses official registries, credentials are limited to standard API key usage, and data flows are consistent with interacting with external AI services and vector stores. No evidence of malicious behavior, unverifiable binaries, or excessive credential exposure beyond typical API key handling was found. Overall risk is low with respect to security posture, though prudent secret management and access controls should be enforced in deployment.
Confidence: 98%
Audit Metadata