ai-rag-pipeline

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill’s described capabilities (RAG pipelines with external tools) align with its stated purpose, but the install pattern (curl|sh from a remote host) is a known security risk and should be replaced with a pinned, verifiable installation process. Data flows involve external services, which is expected for RAG but requires explicit consent, data governance, and minimal-privilege design. Overall, the footprint is plausible for the intended purpose but elevates security risk due to the unsigned remote install and broad external calls; treat as suspicious until a verifiable, auditable install and explicit data-handling policies are provided.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:37 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fai-rag-pipeline%2F@7e1fb7e75fa06d2526dcc700e8a342d9540c9344