langchain-install-auth

Fail

Audited by Socket on Feb 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] This skill is coherent and benign: it provides installation and authentication instructions for LangChain and requests only appropriate API keys. There are no signs of obfuscation, credential exfiltration, third-party proxies, or malicious code. The main security note is the usual advice to avoid committing .env files or placing API keys in insecure storage. Overall classification: benign with low operational risk (secret management).

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 18, 2026, 07:49 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Flangchain-install-auth%2F@7af3b9a9bf6970b4ed2fabedd0936c8bcc914090