vector-db

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The vector-db skill aligns with its stated purpose of storing and querying high-dimensional vectors via a remote API. Its footprint is modest and uses standard, documented HTTP interactions with an API key for authentication. There are no evident download/install chains or credential-forwarding to unknown binaries. Data flows are consistent with a service integration: inputs (embeddings, index config) flow to the API, and results flow back to the consumer. Security concerns are primarily around data sensitivity of embeddings and ensuring secure transport and proper access controls. Overall, the risk is low-to-moderate (benign-to-suspicious in data handling and external exposure) and proportionate to the task.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 05:44 PM
Package URL
pkg:socket/skills-sh/alphaonedev%2Fopenclaw-graph%2Fvector-db%2F@a1861e7bb655a3b979c7db0bac35727f8ef8e1c7