anysearch

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core search capability matches the stated purpose, and there is no local installer or obvious malware behavior, but the skill has a significant credential-handling flaw: it instructs the agent to persist API keys in plaintext by editing SKILL.md. The service endpoint is first-party to the claimed provider rather than a third-party proxy, yet official documentation for the API and auto-registration flow could not be independently confirmed. Main risk is credential exposure and untrusted-content ingestion, not confirmed malicious intent.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Apr 30, 2026, 02:23 AM
Package URL
pkg:socket/skills-sh/anysearch-ai%2Fanysearch-skills%2Fanysearch%2F@440eaff341af905f4a2f42c499139e1f869145c8