qmd

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment describes a benign, locally-focused search tool with ML-enhanced capabilities. Its footprint is coherent with its purpose. While not malicious, the typical supply-chain risks from external model downloads and integration hooks should be mitigated with standard integrity checks and access controls. No evidence of credential harvesting or data exfiltration is present in the provided material.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 09:44 AM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Fqmd%2F@28291a9dbfc24f311c54bc01fb986c2713ac6b87