ai-rag-pipeline
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: The skill’s purpose broadly matches its capabilities, and the installer appears to be official same-org infrastructure rather than an unrelated payload. Main risks are the pipe-to-shell install pattern, broad Bash permission, indirect prompt injection from untrusted web content, service-mediated data flow through inference.sh apps, and transitive installation of other skills.
Confidence: 87%Severity: 56%
Audit Metadata