ai-rag-pipeline

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill’s purpose broadly matches its capabilities, and the installer appears to be official same-org infrastructure rather than an unrelated payload. Main risks are the pipe-to-shell install pattern, broad Bash permission, indirect prompt injection from untrusted web content, service-mediated data flow through inference.sh apps, and transitive installation of other skills.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:45 AM
Package URL
pkg:socket/skills-sh/inferencesh%2Fskills%2Fai-rag-pipeline%2F@3be4496ccafb71335ce5010e43f93ae314c9d5da