brave-search

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a straightforward wrapper/manifest for using a Brave Search MCP server to provide web/news/local/video/image search and summarization. Its requested capabilities (network access to Brave API and an API key) align with the stated purpose. The primary supply-chain risk is the documented npx install of @brave/search-mcp (transitive code execution from npm). The API key requirement is expected but should be handled as a sensitive secret. No evidence of covert exfiltration, obfuscated code, or requests to suspicious domains is present in the provided manifest. Recommended mitigations: obtain API key from official Brave site, verify the npm package integrity (pin version / use lockfile or vendor package), grant the minimal scope to the key, and ensure agent logging does not leak secrets.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 2, 2026, 03:29 PM
Package URL
pkg:socket/skills-sh/mikeng-io%2Fagent-skills%2Fbrave-search%2F@a865b2d52923883d527013a18574de006ab4ef83