lev-find

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The lev-find fragment is a high-coverage orchestration blueprint for multi-backend semantic search and memory recall. It aligns with its stated purpose in broad terms but introduces several supply-chain and data-flow risks: reliance on multiple external research backends with API keys, potential exposure of credentials in docs, and network interactions with local or external endpoints. While not inherently malicious, the footprint is large and increases attack surface, credential exposure risk, and data-management complexity. Treat as SUSPICIOUS to HIGH-RISK due to broad data flow and credential-prone integration, requiring strict access controls, secret management, and clear policy for per-action user consent and auditing of backends.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 09:44 AM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Flev-find%2F@29b51fc4985d5b3753449062474418d0178b9de6