openduck-distributed-duckdb

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities mostly match its distributed DuckDB purpose, but trust is weakened by a publisher/source mismatch, lack of verifiable release provenance, and the need to disable DuckDB extension signature checks. Data flows and token use are proportionate to the product, so this is not confirmed malware, but it carries meaningful supply-chain and execution-trust risk.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 15, 2026, 01:43 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fopenduck-distributed-duckdb%2F@c07e6bd42f5a282c87088c5d57465ab8f9aa214d