Ai Search

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill document is a template/specification for an AI-powered search backend. It contains no executable or network code, no direct calls to external domains, and no hardcoded secrets, so there is no immediate evidence of malicious behavior in the provided content. The main risks are operational: implementers could introduce supply-chain or data-exfiltration vulnerabilities when they select model/embedding providers, configure environment variables, or implement logging/observability. The agent directive that forces terse output is a minor red flag if an automated agent is given powerful execution privileges. Recommend: accept the skill content as documentation only, but enforce secure implementation requirements (pinned/trusted endpoints, secret management, input sanitization, avoid logging PII, explicit approval for any third-party integrations).

Confidence: 75%Severity: 50%
Audit Metadata
Analyzed At
Mar 2, 2026, 09:25 AM
Package URL
pkg:socket/skills-sh/AmnadTaowsoam%2FCerebraSkills%2Fai-search%2F@5e6e42418b2bcb3895793747306b82c5f6a8a233