agent-search

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and data flows largely match a web-search function, and the named provider endpoints appear legitimate. However, the core executable is an undocumented local CLI with unverifiable provenance, and it may receive API keys, so the install/execution trust story is incomplete enough to raise the overall risk.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Mar 15, 2026, 07:37 PM
Package URL
pkg:socket/skills-sh/haiyuan-ai%2Fagent-skills%2Fagent-search%2F@9cae9b5489a980f26287cf11a91b02c1ed8409fa