langsmith-dataset

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill centers on dataset management for LangSmith and includes legitimate patterns (CLI/SDK usage, dataset creation, export, and upload). However, the installation approach via curl | sh from a raw GitHub URL is a notable supply-chain risk, elevating the security risk profile. The credential handling via environment variables is expected for this kind of tool but warrants careful scope-limitation and auditing. Overall, the footprint is coherent with the stated purpose but remains suspicious due to the unverifiable installer pattern; treat as SUSPICIOUS with elevated caution, particularly around installation trust and potential credential exposure through environment/config handling.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:45 PM
Package URL
pkg:socket/skills-sh/langchain-ai%2Fskills-benchmarks%2Flangsmith-dataset%2F@ea9d72b5757bee1f2802cd7d9d054c4d6c25de0e