AgentDB Advanced Features

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill/documentation describes powerful distributed synchronization and vector-search features that are coherent with the stated purpose. It does not contain clear malicious code or obfuscated payloads in the provided text. However, it has moderate supply-chain and operational risk: enabling automatic QUIC synchronization based on environment variables and peer lists without documented peer authentication or certificate management can lead to inadvertent data exfiltration if misconfigured. Using unpinned 'npx agentdb@latest' examples increases supply-chain risk. Recommend operators require explicit secure peer provisioning (mutual TLS, certificate pinning, or token-based auth), avoid running QUIC listeners on public interfaces by default, validate/imported DB contents, and prefer pinned package versions for installs.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:53 AM
Package URL
pkg:socket/skills-sh/frankxai%2Farcanea%2Fagentdb-advanced-features%2F@7276c775649b0bd0cc46e6c0787414c21eb89aab