read-file

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior matches a DuckDB-based file reader, but the footprint is broader than a minimal read utility: it can install extensions, persist secret configuration, and invoke other skills for installation and docs. Data flows mostly align with purpose and do not point to clear exfiltration, but the transitive skill installation and third-party/community extension usage raise medium trust and credential-handling risk.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Apr 1, 2026, 08:19 PM
Package URL
pkg:socket/skills-sh/duckdb%2Fduckdb-skills%2Fread-file%2F@91f67f3876763461ebb4ae9c75ef70d3b37a04a5