last30days
Warn
Audited by Socket on Mar 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Overall, the fragment demonstrates a coherent, purpose-aligned skill for cross-platform social/web research with optional elevated data sources via API keys. Credential handling is local and optional, and data flows involve external data sources with fallback. The most notable risk is potential credential exposure through environment/config files and the handling of user queries/results in logs or transcripts. With proper secret management (avoid logging keys, minimize persistent storage, and consider ephemeral sessions), the risk remains manageable for a research assistant tool. Behavior is benign to moderately elevated depending on data source usage and logging practices.
Confidence: 75%Severity: 75%
Audit Metadata