exa-entities

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The document correctly describes an entity-search/lead-generation skill and provides realistic usage examples. It contains no executable code, hard-coded secrets, or direct indicators of malware. Main risks are: (1) facilitation of large-scale harvesting of personal data (privacy and terms-of-service concerns), and (2) absence of operational security guidance (auth endpoints, credential handling, rate limiting, robots.txt/ToS compliance), which creates uncertainty and a supply-chain review requirement. Recommend: before deploying or using any associated SDK/agent, obtain and review the actual implementation code (network endpoints, auth flows), verify endpoint ownership, enforce rate limits and robots.txt respect, and add explicit guidance for secure credential storage and PII handling.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:33 PM
Package URL
pkg:socket/skills-sh/ejirocodes%2Fagent-skills%2Fexa-entities%2F@08e2c707486758447bab54dc0cd0f9aaf81cd772