ai-rag-pipeline
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s main behavior matches its stated RAG purpose, and the infsh installer appears to be same-org official. Risk comes from unpinned curl|sh installation, broad Bash access, processing untrusted web content with action capability, and explicit transitive installation of other skills.
Confidence: 86%Severity: 56%
Audit Metadata