search-layer

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core search purpose matches most capabilities, but the footprint is broader than a simple search layer. Main concerns are credential forwarding through a local wrapper, support for arbitrary Grok apiUrl instead of a fixed official endpoint, and recursive processing of untrusted external content that creates notable prompt-injection risk. No clear evidence of confirmed malware or overt exfiltration appears in the excerpt.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/blessonism%2Fopenclaw-search-skills%2Fsearch-layer%2F@e5e76ddb1847be3375391d7e1fb8c8db04fceb84