qmd

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The qmd skill as described is coherent with a local Markdown search tool. It emphasizes local indexing, BM25-based searching, and optional semantic/search hybrid modes, all consistent with its stated purpose. The required/install pathway uses a mainstream package manager (Bun) and a GitHub URL, which is common for developer tooling but warrants awareness of source trust and provenance. No credential handling, no obvious data exfiltration, and no external network calls are described in the provided material, aligning with a benign deployment footprint. The primary risks are moderate due to potential supply-chain concerns around direct GitHub installs and the (possible) future use of external embedding/LLM services; otherwise, the risk remains low to moderate and proportional to its local-only functionality.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 12:12 AM
Package URL
pkg:socket/skills-sh/ckorhonen%2Fclaude-skills%2Fqmd%2F@769863367263e5d6513fa3c1a30950aa232d1672