using-xrpc-indexer

Warn

Audited by Socket on Feb 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Download or install from free hosting/deployment platform detected All findings: [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] This skill fragment is coherent with its stated purpose: it issues HTTP GETs to a named XRPC semantic search API and returns results. There is no evidence of obfuscated or intentionally malicious code in the provided text. The main security consideration is privacy: user queries are transmitted to central-production.up.railway.app (a third-party host). If callers expect local-only processing or have strict data handling requirements, this is a notable concern. Overall the fragment appears benign for its stated function but requires trust in the remote endpoint. LLM verification: The skill's behavior is consistent with its stated purpose (semantic search) and the code shown is simple and not directly malicious. However, all data flows go through a third-party Railway-hosted endpoint (central-production.up.railway.app) with no provenance, authentication, or privacy guidance. This creates a realistic risk that sensitive queries or data could be captured by the remote host. If you trust the operator of that endpoint (official comind / team), the skill is likely safe to use.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 13, 2026, 09:48 PM
Package URL
pkg:socket/skills-sh/cpfiffer%2Fcentral%2Fusing-xrpc-indexer%2F@6928c6030c4ae6c553904da9e08315cc1c92cf2b